0.0

CVE-2026-31673 - af_unix: read UNIX_DIAG_VFS data under unix_state_lock

In the Linux kernel, the following vulnerability has been resolved: af_unix: read UNIX_DIAG_VFS data under unix_state_lock Exact UNIX diag lookups hold a reference to the socket, but not to u->path. Meanwhile, unix_release_sock() clears u->path under unix_state_lock() and drops the path reference…

📅 Published: April 25, 2026, 8:46 a.m. 🔄 Last Modified: April 25, 2026, 8:46 a.m.

9.2

CVSS4.0

CVE-2026-6951 -

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the opti…

📅 Published: April 25, 2026, 5 a.m. 🔄 Last Modified: April 25, 2026, 5 a.m.

7.8

CVSS3.1

CVE-2026-42171 -

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references).

📅 Published: April 24, 2026, 9:20 p.m. 🔄 Last Modified: April 24, 2026, 9:21 p.m.

9.1

CVSS3.1

CVE-2026-41248 - Official Clerk JavaScript SDKs: Middleware-based route protection bypass

Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @cle…

📅 Published: April 24, 2026, 9:04 p.m. 🔄 Last Modified: April 24, 2026, 9:04 p.m.

3.1

CVSS3.1

CVE-2026-41488 - angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_size() helper (used by get_num_tokens_from_messages for image token counting) validated URLs for SSRF protection and then fetched them in a separate network operation with independ…

📅 Published: April 24, 2026, 8:57 p.m. 🔄 Last Modified: April 24, 2026, 8:57 p.m.

6.5

CVSS3.1

CVE-2026-41481 - LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the fetch with requests.get() with redirects enabled (the default)…

📅 Published: April 24, 2026, 8:54 p.m. 🔄 Last Modified: April 24, 2026, 8:55 p.m.

10

CVSS3.1

CVE-2026-41478 - Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sy…

📅 Published: April 24, 2026, 8:52 p.m. 🔄 Last Modified: April 24, 2026, 8:52 p.m.

8.8

CVSS4.0

CVE-2026-41473 - CyberPanel < 2.4.4 Unauthenticated API Access via AI Scanner Endpoints

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoi…

📅 Published: April 24, 2026, 8:40 p.m. 🔄 Last Modified: April 24, 2026, 8:40 p.m.

5.3

CVSS4.0

CVE-2026-41472 - CyberPanel < 2.4.4 Stored XSS via AI Scanner Dashboard

CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of Scan…

📅 Published: April 24, 2026, 8:40 p.m. 🔄 Last Modified: April 24, 2026, 8:40 p.m.

7.8

CVSS3.1

CVE-2026-41477 - Deskflow: Local privilege escalation via unauthenticated IPC

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing any local unprivileged user to execute arbitrary …

📅 Published: April 24, 2026, 7:50 p.m. 🔄 Last Modified: April 24, 2026, 7:50 p.m.
Total resulsts: 347742
Page 122 of 34,775
« previous page » next page
Filters