7.5

CVSS3.1

CVE-2026-25058 - Vexa's unauthenticated internal transcript endpoint exposed by default

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns transcript data for any meeting without any authentication or…

📅 Published: April 20, 2026, 4:03 p.m. 🔄 Last Modified: April 23, 2026, 2:11 p.m.

7.2

CVSS3.1

CVE-2026-23774 - OS Command Injection Vulnerability in Dell PowerProtect Data Domain OS

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker w…

📅 Published: April 20, 2026, 3:58 p.m. 🔄 Last Modified: April 23, 2026, 3:19 p.m.

8.8

CVSS3.1

CVE-2026-26944 - Missing Authentication Allows Remote Root Command Execution on Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially e…

📅 Published: April 20, 2026, 3:51 p.m. 🔄 Last Modified: April 23, 2026, 1:59 p.m.

5.3

CVSS3.1

CVE-2026-24468 - OpenAEV Vulnerable to Username/Email Enumeration Through Differential HTTP Responses in Password Re…

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.11.0 and prior to version 2.0.13, the /api/reset endpoint behaves differently depending on whether the supplied username exists in the system.…

📅 Published: April 20, 2026, 3:45 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

9.1

CVSS3.1

CVE-2026-24467 - OpenAEV's Improper Password Reset Token Management Leads to Unauthenticated Account Takeover and Pl…

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's password reset implementation contains multiple security weaknesses that together allow reliable ac…

📅 Published: April 20, 2026, 3:40 p.m. 🔄 Last Modified: April 23, 2026, 2:38 p.m.

7.1

CVSS3.1

CVE-2026-6066 - Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center

ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where certain client-to-server communications could occur without transport-layer encryption. This could allow network‑based interception of Solution Center tra…

📅 Published: April 20, 2026, 3:26 p.m. 🔄 Last Modified: April 23, 2026, 2:18 p.m.

5.9

CVSS3.1

CVE-2026-41245 - Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix

Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes th…

📅 Published: April 20, 2026, 3:15 p.m. 🔄 Last Modified: April 23, 2026, 1:35 p.m.

6.5

CVSS3.1

CVE-2026-40896 - OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup

OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project can inject agenda items into meetings belonging to any other project on the instance — even projects they have no access to. No knowledge of the target …

📅 Published: April 20, 2026, 3:12 p.m. 🔄 Last Modified: April 23, 2026, 1:45 p.m.

5.1

CVSS4.0

CVE-2026-6652 - Pagekit CMS StringStorage Template PhpEngine.php evaluate eval injection

A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutralization of directives in dynamically evaluated code. Remote e…

📅 Published: April 20, 2026, 3 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

4.6

CVSS4.0

CVE-2026-3219 - pip doesn't reject concatenated ZIP and tar archives

pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with …

📅 Published: April 20, 2026, 2:55 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.
Total resulsts: 346531
Page 123 of 34,654
« previous page » next page
Filters