8.9

CVSS3.1

CVE-2026-40487 - Postiz Has Unrestricted File Upload via MIME Type Spoofing that Leads to Stored XSS

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a …

πŸ“… Published: April 18, 2026, 1:19 a.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

8.8

CVSS3.1

CVE-2026-35582 - Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /bin/sh -c shell command string without any escaping or input validation. The IN_FILE_ENDING and OUT_F…

πŸ“… Published: April 18, 2026, 1:16 a.m. πŸ”„ Last Modified: April 24, 2026, 4:48 p.m.

7.5

CVSS3.1

CVE-2026-35465 - SecureDrop Client has path injection in read_gzip_header_filename()

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper file…

πŸ“… Published: April 18, 2026, 12:41 a.m. πŸ”„ Last Modified: April 23, 2026, 6:31 p.m.

9

CVSS3.1

CVE-2026-40572 - NovumOS has Arbitrary Memory Mapping via Syscall 15 (MemoryMapRange)

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions, including critical ker…

πŸ“… Published: April 18, 2026, 12:16 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

9.4

CVSS3.1

CVE-2026-40317 - NovumOS has Privilege Escalation in the Syscall Interface

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allowing any Ring 3 user-mode process to jump to kernel addresses and execute arbitr…

πŸ“… Published: April 18, 2026, 12:12 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

8.8

CVSS3.1

CVE-2026-40350 - Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users …

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the route de…

πŸ“… Published: April 18, 2026, 12:07 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

8.8

CVSS3.1

CVE-2026-40349 - Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Se…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a use…

πŸ“… Published: April 18, 2026, 12:05 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

4.8

CVSS3.1

CVE-2026-40593 - ChurchCRM: Stored XSS in UserEditor.php via Login Name Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking charac…

πŸ“… Published: April 18, 2026, 12:02 a.m. πŸ”„ Last Modified: April 20, 2026, 6:59 p.m.

7.7

CVSS3.1

CVE-2026-40348 - Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Pro…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoint accepts a user-controlled URL, appends …

πŸ“… Published: April 18, 2026, 12:01 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

5.3

CVSS3.1

CVE-2026-40347 - Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candi…

πŸ“… Published: April 17, 2026, 11:56 p.m. πŸ”„ Last Modified: April 24, 2026, 4:51 p.m.
Total resulsts: 346535
Page 140 of 34,654
Β« previous page Β» next page
Filters