6.9

CVSS4.0

CVE-2026-40299 - next-intl has an open redirect vulnerability

next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//`…

📅 Published: April 17, 2026, 8:49 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

6.5

CVSS3.1

CVE-2026-40293 - OpenFGA Playground Preshared Key Exposure

OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint…

📅 Published: April 17, 2026, 8:47 p.m. 🔄 Last Modified: April 22, 2026, 6:15 a.m.

5.4

CVSS4.0

CVE-2026-35603 - Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windo…

Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData directory is writable by…

📅 Published: April 17, 2026, 8:38 p.m. 🔄 Last Modified: April 22, 2026, 6:45 p.m.

2.3

CVSS4.0

CVE-2026-35402 - mcp-neo4j-cypher: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures

mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This issue is fixed in ve…

📅 Published: April 17, 2026, 8:34 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

3.1

CVSS3.1

CVE-2026-33436 - Stirling-PDF: Reflected XSS through crafted filename in file upload functionality

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames directly into HTML using unsafe methods like innerHTML without sanitization. An attacker can craft a file with a malici…

📅 Published: April 17, 2026, 8:29 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

7.5

CVSS3.1

CVE-2026-40286 - WeGIA has Cross-Site Scripting in Controle de Contribuição

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) function. By injecting a payload into the 'Member Name' (Nome Sócio) field, the script is persistently sto…

📅 Published: April 17, 2026, 8:27 p.m. 🔄 Last Modified: April 20, 2026, 7:02 p.m.

9.4

CVSS4.0

CVE-2026-23500 - Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sa…

📅 Published: April 17, 2026, 8:25 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

8.8

CVSS3.1

CVE-2026-40285 - WeGIA has SQL Injection via Session Variable Override in DespachoControle.php

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the session-stored user identity via extract($_REQUEST) in DespachoControle::verificarDespacho(), and the att…

📅 Published: April 17, 2026, 8:25 p.m. 🔄 Last Modified: April 20, 2026, 7:02 p.m.

8.5

CVSS4.0

CVE-2026-40527 - radare2 Command Injection via DWARF Parameter Names

radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences as DWARF DW_TAG_formal_parameter names. Attackers can craft a binary with shell commands in DWARF parameter names that execut…

📅 Published: April 17, 2026, 8:25 p.m. 🔄 Last Modified: April 20, 2026, 7:05 p.m.

6.8

CVSS3.1

CVE-2026-40284 - WeGIA has stored XSS in listar_despachos.php

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the "Destinatário" field. The payload is stored and later executed when viewing the dispatch page, impac…

📅 Published: April 17, 2026, 8:24 p.m. 🔄 Last Modified: April 20, 2026, 7:02 p.m.
Total resulsts: 346279
Page 120 of 34,628
« previous page » next page
Filters