5.7

CVSS3.1

CVE-2026-35451 - Twenty: Stored XSS via BlockNote FileBlock

Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock component and insufficient server-side inspection of block content, an attacker can inject a javascript: U…

πŸ“… Published: April 21, 2026, 4:22 p.m. πŸ”„ Last Modified: April 22, 2026, 9:17 p.m.

3.3

CVSS3.1

CVE-2026-29179 - October: Editor Sub-Permission Bypass for Asset and Blueprint File Operations

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend users who were explicitly granted editor access …

πŸ“… Published: April 21, 2026, 4:19 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

8.2

CVSS3.1

CVE-2026-24189 - Unauthenticated Out-of-Bounds Read in NVIDIA CUDA-Q Endpoint

NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

πŸ“… Published: April 21, 2026, 4:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.7

CVSS3.1

CVE-2026-24177 - Unauthorized API Access Leading to Information Disclosure in NVIDIA KAI Scheduler

NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure.

πŸ“… Published: April 21, 2026, 4:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

3.1

CVSS3.1

CVE-2026-27937 - October: Reflected XSS via DataTable Form Widget

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 a…

πŸ“… Published: April 21, 2026, 4:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

4.3

CVSS3.1

CVE-2026-24176 - Improper Authorization Enabling Data Tampering via Cross‑Namespace Pod References in NVIDIA KAI Sch…

NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering.

πŸ“… Published: April 21, 2026, 4:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.6

CVSS3.1

CVE-2026-26274 - October: Safe Mode Bypass via Twig Database Write Operations

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup…

πŸ“… Published: April 21, 2026, 4:16 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

4.9

CVSS3.1

CVE-2026-26067 - October: Safe Mode Bypass via CSS Preprocessor Compilers

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the co…

πŸ“… Published: April 21, 2026, 4:16 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

9.3

CVSS4.0

CVE-2019-25714 - Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write…

πŸ“… Published: April 21, 2026, 4:11 p.m. πŸ”„ Last Modified: April 22, 2026, 9:20 p.m.

8.5

CVSS3.1

CVE-2026-40568 - FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature. The sanitization function `Helper::stripDangerousTags()` (`app/Misc/Helper.php:568`) uses an incomplete blocklist of only …

πŸ“… Published: April 21, 2026, 4:08 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.
Total resulsts: 346770
Page 126 of 34,677
Β« previous page Β» next page
Filters