7.6

CVSS3.1

CVE-2026-41419 - 4ga Boards: Import Path Traversal Leads to Arbitrary File Read

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbitrary host files as board attachments during BOARDS archive import. Once imported, the file can be do…

πŸ“… Published: April 24, 2026, 6:50 p.m. πŸ”„ Last Modified: April 24, 2026, 6:50 p.m.

5.3

CVSS3.1

CVE-2026-41418 - 4ga Boards: User Enumeration via Timing Side-Channel in Authentication Endpoint

4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately (~17ms average). When a …

πŸ“… Published: April 24, 2026, 6:49 p.m. πŸ”„ Last Modified: April 24, 2026, 6:49 p.m.

8.2

CVSS4.0

CVE-2026-41326 - Kata Containers: CopyFile Policy Subversion via Symlinks

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations i…

πŸ“… Published: April 24, 2026, 6:46 p.m. πŸ”„ Last Modified: April 24, 2026, 6:46 p.m.

8.1

CVSS4.0

CVE-2026-41416 - PJSIP: Asymmetric ptime integer overflow in Media Stream

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream buffer size calculation when processing SDP with asymmetric ptime configuration. The overflow may result in an undersized buffer allocation, which can lea…

πŸ“… Published: April 24, 2026, 6:40 p.m. πŸ”„ Last Modified: April 24, 2026, 6:40 p.m.

6.7

CVSS4.0

CVE-2026-41415 - PJSIP: SIP Multipart CID URI Length Underflow

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerabil…

πŸ“… Published: April 24, 2026, 6:38 p.m. πŸ”„ Last Modified: April 24, 2026, 6:38 p.m.

7.4

CVSS3.1

CVE-2026-41414 - Skim: Arbitrary code execution via pull_request_target fork checkout in pr.yml

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT_PRIVATE_KEY and GITHUB_TOKEN (contents:write). No gates prevent exploitation -…

πŸ“… Published: April 24, 2026, 6:32 p.m. πŸ”„ Last Modified: April 24, 2026, 6:32 p.m.

9.8

CVSS3.1

CVE-2026-41492 - Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker can retri…

πŸ“… Published: April 24, 2026, 6:29 p.m. πŸ”„ Last Modified: April 24, 2026, 6:29 p.m.

9.1

CVSS3.1

CVE-2026-41327 - Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack is a sing…

πŸ“… Published: April 24, 2026, 6:27 p.m. πŸ”„ Last Modified: April 24, 2026, 6:27 p.m.

9.1

CVSS3.1

CVE-2026-41328 - Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requires …

πŸ“… Published: April 24, 2026, 6:25 p.m. πŸ”„ Last Modified: April 24, 2026, 6:25 p.m.

7.5

CVSS3.1

CVE-2026-33666 - Zserio: Integer Overflow in BitStreamReader on 32-bit platforms

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), the setBitPosition() bounds check receives the overflowed value and is completely bypassed. The code then reads len bytes (512 …

πŸ“… Published: April 24, 2026, 6:21 p.m. πŸ”„ Last Modified: April 24, 2026, 6:21 p.m.
Total resulsts: 347766
Page 127 of 34,777
Β« previous page Β» next page
Filters