0.0

CVE-2026-5760 - CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered using an unsandboxed jinja2.Environment().

📅 Published: April 20, 2026, 1:46 p.m. 🔄 Last Modified: April 20, 2026, 1:46 p.m.

5.7

CVSS4.0

CVE-2026-6369 - Exposed Session Token in canonical-livepatch client snap

An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exp…

📅 Published: April 20, 2026, 1:38 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

8.4

CVSS3.1

CVE-2026-4048 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Man…

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

📅 Published: April 20, 2026, 1:36 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

8.4

CVSS3.1

CVE-2026-3519 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Man…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command

📅 Published: April 20, 2026, 1:32 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

5.3

CVSS4.0

CVE-2026-6649 - Qibo CMS headers server-side request forgery

A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/image/headers. Executing a manipulation of the argument starts can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclose…

📅 Published: April 20, 2026, 1:30 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

8.4

CVSS3.1

CVE-2026-3518 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Man…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

📅 Published: April 20, 2026, 1:29 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

9.1

CVSS3.1

CVE-2026-33557 - Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience…

📅 Published: April 20, 2026, 1:28 p.m. 🔄 Last Modified: April 22, 2026, 2:14 p.m.

5.3

CVSS3.1

CVE-2025-66335 - Apache Doris MCP Server: MCP SQL inject

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.…

📅 Published: April 20, 2026, 1:27 p.m. 🔄 Last Modified: April 22, 2026, 2:17 p.m.

8.4

CVSS3.1

CVE-2026-3517 - OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Man…

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

📅 Published: April 20, 2026, 1:22 p.m. 🔄 Last Modified: April 22, 2026, 11:48 a.m.

5.3

CVSS3.1

CVE-2026-33558 - Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information wil…

📅 Published: April 20, 2026, 1:20 p.m. 🔄 Last Modified: April 22, 2026, 2:16 p.m.
Total resulsts: 346535
Page 125 of 34,654
« previous page » next page
Filters