6.3

CVSS4.0

CVE-2026-41455 - WeKan < 8.35 SSRF via Webhook URL

WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without protocol restriction or destination validation. Attackers who can create or modify integrations can set webhook URLs to internal network a…

📅 Published: April 22, 2026, 9:09 p.m. 🔄 Last Modified: April 23, 2026, 4:27 p.m.

8.7

CVSS4.0

CVE-2026-41454 - WeKan < 8.35 Missing Authorization via Integration REST API

WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authenticated board members to perform administrative actions without proper privilege verification. Attackers can enumerate integrations including webhook URLs, create new integration…

📅 Published: April 22, 2026, 9:08 p.m. 🔄 Last Modified: April 23, 2026, 4:27 p.m.

4.8

CVSS4.0

CVE-2026-41314 - pypdf: Manipulated FlateDecode image dimensions can exhaust RAM

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values. This has been fixed in pypdf 6.10.2…

📅 Published: April 22, 2026, 9:08 p.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.

4.8

CVSS4.0

CVE-2026-41313 - pypdf: Possible long runtimes for wrong size values in incremental mode

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode. This has been fixed in pypdf 6.10.2. As…

📅 Published: April 22, 2026, 9:04 p.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.

4.8

CVSS4.0

CVE-2026-41312 - pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predicto…

📅 Published: April 22, 2026, 9:02 p.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.

6.9

CVSS4.0

CVE-2026-41168 - pypdf has possible long runtimes for wrong size values in cross-reference and object streams

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values. This …

📅 Published: April 22, 2026, 8:49 p.m. 🔄 Last Modified: April 24, 2026, 1:07 p.m.

9.1

CVSS3.1

CVE-2026-41167 - Jellystat has SQL Injection that leads to to Remote Code Execution

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly into raw SQL strings. An authenticated user can inject arbitrary SQL via `POST /api/getUserDetail…

📅 Published: April 22, 2026, 8:39 p.m. 🔄 Last Modified: April 23, 2026, 3:37 p.m.

7.6

CVSS3.1

CVE-2026-40882 - OpenRemote has XXE in Velbus Asset Import

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-…

📅 Published: April 22, 2026, 8:33 p.m. 🔄 Last Modified: April 24, 2026, 1:24 p.m.

7

CVSS3.1

CVE-2026-41166 - OpenRemote has Improper Access Control via updateUserRealmRoles function

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users in another realm, including `master`. The handler uses the `{realm}` path segment when talking to t…

📅 Published: April 22, 2026, 8:31 p.m. 🔄 Last Modified: April 25, 2026, 3:55 a.m.

7.3

CVSS4.0

CVE-2026-41134 - Kiota: Code Generation Literal Injection

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/property metadata, a…

📅 Published: April 22, 2026, 8:20 p.m. 🔄 Last Modified: April 25, 2026, 3:55 a.m.
Total resulsts: 347382
Page 134 of 34,739
« previous page » next page
Filters