7.2

CVSS3.1

CVE-2026-24506 - OS Command Injection in Dell PowerProtect Data Domain Enables Arbitrary Root Execution

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabilit…

πŸ“… Published: April 20, 2026, 4:22 p.m. πŸ”„ Last Modified: April 22, 2026, 3:56 a.m.

5.3

CVSS4.0

CVE-2026-40098 - OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option d…

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-cart endpoint authorizes access with a public `sh…

πŸ“… Published: April 20, 2026, 4:19 p.m. πŸ”„ Last Modified: April 23, 2026, 5:46 p.m.

8.7

CVSS4.0

CVE-2026-41445 - KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()

KissFFT before commitΒ 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc(…

πŸ“… Published: April 20, 2026, 4:18 p.m. πŸ”„ Last Modified: April 22, 2026, 11:47 a.m.

7.2

CVSS3.1

CVE-2026-24505 - Improper Input Validation Allows Remote Command Execution on Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

πŸ“… Published: April 20, 2026, 4:15 p.m. πŸ”„ Last Modified: April 22, 2026, 3:56 a.m.

4.9

CVSS3.1

CVE-2026-25525 - OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the Dataflow module in OpenMage LTS uses a weak blacklist filter (`str_repla…

πŸ“… Published: April 20, 2026, 4:14 p.m. πŸ”„ Last Modified: April 23, 2026, 5:47 p.m.

8.1

CVSS3.1

CVE-2026-25524 - OpenMage LTS's Phar Deserialization leads to Remote Code Execution

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, PHP functions such as `getimagesize()`, `file_exists()`, and `is_readable()`…

πŸ“… Published: April 20, 2026, 4:11 p.m. πŸ”„ Last Modified: April 23, 2026, 5:47 p.m.

7.2

CVSS3.1

CVE-2026-24504 - Improper Input Validation Leading to Arbitrary Command Execution in Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnera…

πŸ“… Published: April 20, 2026, 4:08 p.m. πŸ”„ Last Modified: April 22, 2026, 3:55 a.m.

5.8

CVSS3.1

CVE-2026-25883 - Vexa Webhook Feature has a SSRF Vulnerability

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa webhook feature allows authenticated users to configure an arbitrary URL that receives HTTP POST requests when meetings complete. The application performs no validation on the …

πŸ“… Published: April 20, 2026, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 2:10 p.m.

7.5

CVSS3.1

CVE-2026-25058 - Vexa's unauthenticated internal transcript endpoint exposed by default

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns transcript data for any meeting without any authentication or…

πŸ“… Published: April 20, 2026, 4:03 p.m. πŸ”„ Last Modified: April 23, 2026, 2:11 p.m.

7.2

CVSS3.1

CVE-2026-23774 - OS Command Injection Vulnerability in Dell PowerProtect Data Domain OS

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker w…

πŸ“… Published: April 20, 2026, 3:58 p.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.
Total resulsts: 346529
Page 122 of 34,653
Β« previous page Β» next page
Filters