5.1

CVSS4.0

CVE-2026-6745 - Bagisto Custom Scripts cross site scripting

A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may bโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:30 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 7 a.m.

8.1

CVSS3.1

CVE-2026-40868 - kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyvernoโ€™s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a policy does not explicitly set an Authorization header. Becausโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:22 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.1

CVSS4.0

CVE-2026-40867 - Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files anโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:16 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:05 p.m.

8.6

CVSS4.0

CVE-2026-40866 - Horilla: Unauthorized Document Overwrite via File Upload Endpoint

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employeeโ€™s document by changing the document ID in the upload reโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:15 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:05 p.m.

7.1

CVSS4.0

CVE-2026-40865 - Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employeesโ€™ uploaded documents by changing the document ID in the request. This exposes sensitive HR โ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:14 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:05 p.m.

8.5

CVSS4.0

CVE-2026-40614 - PJSIP: Heap buffer overflow in Opus codec decoding

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames due to insufficient buffer size validation in the Opus codec decode path. The FEC decode buffers (dec_frame[].buf) were allocated based on aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:04 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 4:09 p.m.

5.1

CVSS4.0

CVE-2026-41456 - Bludit CMS Reflected XSS via Search Plugin

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit craftโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6:03 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:20 p.m.

7.5

CVSS3.1

CVE-2026-40613 - Coturn: Misaligned Memory Access in coturn STUN Attribute Parser (Remote DoS on ARM64)

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t * to uint16_t * without alignment checks. When processing a crafted STUN message with odd-aligned attribute boundaries,โ€ฆ

๐Ÿ“… Published: April 21, 2026, 6 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 1:41 p.m.

5.3

CVSS4.0

CVE-2026-6744 - Bagisto Downloadable Link copy server-side request forgery

A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted earโ€ฆ

๐Ÿ“… Published: April 21, 2026, 6 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1:27 p.m.

8.8

CVSS3.1

CVE-2026-40611 - Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider

Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to wโ€ฆ

๐Ÿ“… Published: April 21, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:17 p.m.
Total resulsts: 346692
Page 114 of 34,670
ยซ previous page ยป next page
Filters