6.9

CVSS4.0

CVE-2026-6588 - serge-chat serge Model API Endpoint model.py delete_model missing authentication

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched re…

πŸ“… Published: April 20, 2026, 12:15 a.m. πŸ”„ Last Modified: April 20, 2026, 12:15 a.m.

5.3

CVSS4.0

CVE-2026-6587 - vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argu…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, midnight

0.0

CVE-2026-39109 -

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:18 p.m.

0.0

CVE-2026-39111 -

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:20 p.m.

4.3

CVSS3.1

CVE-2026-41285 - Infinite Loop in OpenBSD SLAACD and RAD Daemons Due to Zero-Length ICMPv6 ND Option

In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expression with no preceding check for whether nd_opt_len is zero.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 6:59 p.m.

0.0

CVE-2026-39112 -

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisito…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:20 p.m.

6.6

CVSS3.1

CVE-2026-31430 - X.509: Fix out-of-bounds access when parsing extensions

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty Basic Constraints or Key Usage extension because the first byte of the extension is read before che…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:17 p.m.

0.0

CVE-2026-39110 -

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve se…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:19 p.m.

8.8

CVSS3.1

CVE-2026-29648 - Privilege Escalation via Improper CSRs Access in OpenXiangShan NEMU

In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privileged code may read or write these CSRs without the required exception, potentially bypassing intended state-enable based isolation controls …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 7:45 a.m.

7.8

CVSS3.1

CVE-2026-30266 - Local Arbitrary Code Execution via Insecure Permissions in DeepCool DeepCreative

Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 1:40 p.m.
Total resulsts: 346514
Page 131 of 34,652
Β« previous page Β» next page
Filters