8.2

CVSS4.0

CVE-2026-40481 - monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validat…

monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST payloads to cause uncontrolled mem…

📅 Published: April 17, 2026, 10:54 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

4.3

CVSS3.1

CVE-2026-40486 - Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, in…

Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields a…

📅 Published: April 17, 2026, 10:35 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

5.4

CVSS3.1

CVE-2026-40479 - Kimai: Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype and…

📅 Published: April 17, 2026, 10:31 p.m. 🔄 Last Modified: April 18, 2026, 9 a.m.

6.4

CVSS3.1

CVE-2026-2434 - Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

📅 Published: April 17, 2026, 10:27 p.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

9.1

CVSS3.1

CVE-2026-40478 - Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly ne…

📅 Published: April 17, 2026, 9:57 p.m. 🔄 Last Modified: April 22, 2026, 3:55 a.m.

9.1

CVSS3.1

CVE-2026-40477 - Improper restriction of the scope of accessible objects in Thymeleaf expressions

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restri…

📅 Published: April 17, 2026, 9:53 p.m. 🔄 Last Modified: April 22, 2026, 3:55 a.m.

6.9

CVSS4.0

CVE-2026-40476 - graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation

graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU…

📅 Published: April 17, 2026, 9:42 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

7.1

CVSS4.0

CVE-2026-5720 - miniupnpd Integer Underflow SOAPAction Header Parsing

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger an out-of-bounds memory read by exploiting impro…

📅 Published: April 17, 2026, 9:39 p.m. 🔄 Last Modified: April 20, 2026, 7:05 p.m.

7.6

CVSS3.1

CVE-2026-40474 - wger has Broken Access Control in the Global Gym Configuration Update Endpoint

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permission is never enforced at runtime. Since GymConfig is an owner…

📅 Published: April 17, 2026, 9:39 p.m. 🔄 Last Modified: April 24, 2026, 2:46 p.m.

5.1

CVSS4.0

CVE-2026-40353 - wger: Stored XSS via Unescaped License Attribution Fields

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django'…

📅 Published: April 17, 2026, 9:16 p.m. 🔄 Last Modified: April 24, 2026, 2:46 p.m.
Total resulsts: 346442
Page 134 of 34,645
« previous page » next page
Filters