6.1

CVSS3.1

CVE-2026-6861 - Emacs: emacs: memory corruption vulnerability when processing svg css

A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a deniโ€ฆ

๐Ÿ“… Published: April 19, 2026, midnight ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

9.4

CVSS4.0

CVE-2026-41242 - protobufjs has an arbitrary code execution issue

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the iโ€ฆ

๐Ÿ“… Published: April 18, 2026, 4:18 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:26 p.m.

5.4

CVSS3.1

CVE-2026-40948 - Apache Airflow Providers Keycloak: OAuth Login CSRF โ€” Missing State Parameter in Keycloak Auth Manaโ€ฆ

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's โ€ฆ

๐Ÿ“… Published: April 18, 2026, 1:22 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:05 p.m.

6.4

CVSS3.1

CVE-2026-2986 - Contextual Related Posts <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'oโ€ฆ

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributoโ€ฆ

๐Ÿ“… Published: April 18, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.4

CVSS3.1

CVE-2026-2505 - Categories Images <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'z_taxonoโ€ฆ

The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_image' shortcode. This is due to the shortcode rendering path passing attacker-controlled class input into a fallback image builder that concatenates โ€ฆ

๐Ÿ“… Published: April 18, 2026, 9:26 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:22 p.m.

6.4

CVSS3.1

CVE-2026-0894 - Content Blocks (Custom Post Widget) <= 3.3.9 - Authenticated (Author+) Stored Cross-Site Scripting โ€ฆ

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied values consumed from user-createโ€ฆ

๐Ÿ“… Published: April 18, 2026, 9:26 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:22 p.m.

4

CVSS3.1

CVE-2026-41254 - Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via inteโ€ฆ

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

๐Ÿ“… Published: April 18, 2026, 6:43 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 6:34 p.m.

3.7

CVSS3.1

CVE-2026-32690 - Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apโ€ฆ

๐Ÿ“… Published: April 18, 2026, 6:22 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 2:41 p.m.

8.8

CVSS3.1

CVE-2026-30898 - Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advicโ€ฆ

๐Ÿ“… Published: April 18, 2026, 6:20 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 3:55 a.m.

7.5

CVSS3.1

CVE-2026-30912 - Apache Airflow: Exposing stack trace in case of constraint error

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

๐Ÿ“… Published: April 18, 2026, 6:20 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 2:42 p.m.
Total resulsts: 346529
Page 137 of 34,653
ยซ previous page ยป next page
Filters