6.5

CVSS3.1

CVE-2026-35173 - Chyrp Lite has an IDOR via Mass Assignment in Post Model

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post, Edit Draft, Edit Own Post, Edit Own Draft) to modify posts they do not own and do not have permissโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:48 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

9.8

CVSS3.1

CVE-2026-35171 - Arbitrary Code Execution via Malicious Logging Configuration in Kedro

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without validation. The logging configuration schema supports the special () key, which enables arbitrary cโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5672 - code-projects Simple IT Discussion Forum Parameter edit-category.php sql injection

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_id leads to sql injection. It is possible to initiate the attaโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 9:37 a.m.

7.1

CVSS3.1

CVE-2026-35167 - Kedro has a path traversal in versioned dataset loading via unsanitized version string

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.py constructs filesystem paths by directly interpolating user-supplied version strings without sanitization. Because version strings are used as path components, traversal sequencโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:43 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:36 p.m.

8.8

CVSS3.1

CVE-2026-35470 - OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability. The righe parameter received via $_GET['righe'] is directly concatenated into anโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:40 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-35166 - Hugo does not properly escape some Markdown links

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.15โ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:37 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.8

CVSS3.1

CVE-2026-35164 - Brave CMS Sffected by Unrestricted File Upload via CKEditor Endpoint

Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entireโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:33 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-35052 - D-Tale affected by Remote Code Execution through redis/shelf storage

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the serverโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:32 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

9.1

CVSS3.1

CVE-2026-35050 - text-generation-webui affected by Remote Code Execution (RCE) through Path Traversal at "Session ->โ€ฆ

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in "py" format and in the app root directory. This allows to overwrite python files, for instance the "download-model.py" file could be overwritten. Then, this โ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:30 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:30 p.m.

7.5

CVSS3.1

CVE-2026-35209 - defu: Prototype pollution via `__proto__` key in defaults argument

defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototypeโ€ฆ

๐Ÿ“… Published: April 6, 2026, 5:26 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343923
Page 138 of 34,393
ยซ previous page ยป next page
Filters