5.3

CVSS4.0

CVE-2026-6874 - ericc-ch copilot-api Header token dns rebinding

A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing a manipulation of the argument Host can lead to reliance on reverse dns resolution. The attack may be performed from remote. The exploit…

πŸ“… Published: April 22, 2026, 11:30 p.m. πŸ”„ Last Modified: April 28, 2026, 12:15 a.m.

7.3

CVSS3.1

CVE-2026-5935 - TSSC/IMC is vulnerable to OS Command Injection

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMCΒ could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.

πŸ“… Published: April 22, 2026, 11:30 p.m. πŸ”„ Last Modified: April 24, 2026, 2:50 p.m.

4.9

CVSS3.1

CVE-2026-4917 - IBM Guardium Data Protection is affected by multiple vulnerabilities

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.

πŸ“… Published: April 22, 2026, 11:27 p.m. πŸ”„ Last Modified: April 24, 2026, 2:50 p.m.

5.5

CVSS3.1

CVE-2026-4918 - IBM Guardium Data Protection is affected by multiple vulnerabilities

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: April 22, 2026, 11:26 p.m. πŸ”„ Last Modified: April 24, 2026, 2:50 p.m.

4.8

CVSS3.1

CVE-2026-4919 - IBM Guardium Data Protection is affected by multiple vulnerabilities

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: April 22, 2026, 11:23 p.m. πŸ”„ Last Modified: April 24, 2026, 2:50 p.m.

7.5

CVSS3.1

CVE-2026-3621 - IBM WebSphere Application Server Liberty is affected by identity spoofing

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deployed without authentication and authorization configured.

πŸ“… Published: April 22, 2026, 11:07 p.m. πŸ”„ Last Modified: April 24, 2026, 2:50 p.m.

8.4

CVSS4.0

CVE-2026-40517 - radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names

radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with newline characters in symbol names. Attackers can inject arbitrary radare2 commands through unsaniti…

πŸ“… Published: April 22, 2026, 9:44 p.m. πŸ”„ Last Modified: April 27, 2026, 5:04 p.m.

8.1

CVSS3.1

CVE-2026-41175 - Statamic: Unsafe method invocation via query value resolution allows data destruction

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requ…

πŸ“… Published: April 22, 2026, 9:25 p.m. πŸ”„ Last Modified: April 24, 2026, 2:50 p.m.

5.5

CVSS3.1

CVE-2026-41177 - Squidex has Blind SSRF via file:// Protocol in Restore API leading to Local File Interaction

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url` parameter, allowing the us…

πŸ“… Published: April 22, 2026, 9:24 p.m. πŸ”„ Last Modified: April 27, 2026, 8:15 p.m.

7.3

CVSS4.0

CVE-2026-41172 - Squidex vulnerable to Server-Side Request Forgery (SSRF) via URL-based asset upload (/api/apps/{app…

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and persist the response as an…

πŸ“… Published: April 22, 2026, 9:22 p.m. πŸ”„ Last Modified: April 24, 2026, 2:45 p.m.
Total resulsts: 347374
Page 132 of 34,738
Β« previous page Β» next page
Filters