7.6

CVSS4.0

CVE-2026-35568 - MCP Java-SDK has a DNS Rebinding Vulnerability

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or …

πŸ“… Published: April 7, 2026, 9:06 p.m. πŸ”„ Last Modified: April 8, 2026, 7:45 p.m.

7.8

CVSS3.1

CVE-2026-35533 - mise has a local settings bypass config trust checks

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and…

πŸ“… Published: April 7, 2026, 9:01 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

6.8

CVSS4.0

CVE-2026-34080 - xdg-dbus-proxy has an eavesdrop filter bypass allowing message interception

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=true in policy rules but fails to handle eavesdrop ='true' (with a space before the equals sign) and similar cases. Client…

πŸ“… Published: April 7, 2026, 8:57 p.m. πŸ”„ Last Modified: April 11, 2026, 1:34 a.m.

8.2

CVSS3.1

CVE-2026-34045 - Podman Desktop WebView Server Exposed

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection lim…

πŸ“… Published: April 7, 2026, 8:52 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

9.3

CVSS4.0

CVE-2026-33439 - Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the jato.clientSession HTTP parameter. This bypasses the WhitelistObjectInputStream mitig…

πŸ“… Published: April 7, 2026, 8:46 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

5.4

CVSS3.1

CVE-2026-32712 - Open Source Point of Sale has Stored XSS in Customer Name (Sales)

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-tab…

πŸ“… Published: April 7, 2026, 8:37 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

7.5

CVSS3.1

CVE-2026-29181 - OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos a…

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, …

πŸ“… Published: April 7, 2026, 8:29 p.m. πŸ”„ Last Modified: April 8, 2026, 7:45 p.m.

2

CVSS3.1

CVE-2026-27949 - Plane Exposes User Email (PII and part of credential) in GET Parameter

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally i…

πŸ“… Published: April 7, 2026, 8:26 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

5.3

CVSS4.0

CVE-2026-39401 - Privilege Escalation via update_event Job Output in Cronicle

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privileg…

πŸ“… Published: April 7, 2026, 8:24 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.

5.3

CVSS4.0

CVE-2026-39400 - Stored XSS via Job HTML/Table Output in Cronicle

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges can inject arbitrary JavaScript through job output fields (html.content, html.title, table.header, table.rows, table.caption). The ser…

πŸ“… Published: April 7, 2026, 8:22 p.m. πŸ”„ Last Modified: April 8, 2026, 7:34 p.m.
Total resulsts: 343980
Page 107 of 34,398
Β« previous page Β» next page
Filters