8.8

CVSS3.1

CVE-2026-40349 - Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Se…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a use…

πŸ“… Published: April 18, 2026, 12:05 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

4.8

CVSS3.1

CVE-2026-40593 - ChurchCRM: Stored XSS in UserEditor.php via Login Name Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking charac…

πŸ“… Published: April 18, 2026, 12:02 a.m. πŸ”„ Last Modified: April 20, 2026, 6:59 p.m.

7.7

CVSS3.1

CVE-2026-40348 - Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Pro…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoint accepts a user-controlled URL, appends …

πŸ“… Published: April 18, 2026, 12:01 a.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

5.3

CVSS3.1

CVE-2026-40347 - Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candi…

πŸ“… Published: April 17, 2026, 11:56 p.m. πŸ”„ Last Modified: April 24, 2026, 4:51 p.m.

6.4

CVSS4.0

CVE-2026-40346 - NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An aut…

πŸ“… Published: April 17, 2026, 11:54 p.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

8.1

CVSS3.1

CVE-2026-40581 - ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft a…

πŸ“… Published: April 17, 2026, 11:51 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

5.1

CVSS3.1

CVE-2026-40337 - Sentry kernel has incomplete ownership check for IRQ line manipulation

The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to interact with another task's IRQ line through the __sys_int_* syscall familly. Prior to version 0.4.7, this can lead to DoS an…

πŸ“… Published: April 17, 2026, 11:51 p.m. πŸ”„ Last Modified: April 20, 2026, 7:03 p.m.

3.5

CVSS3.1

CVE-2026-40341 - libgphoto2 has an OOB Read in ptp_unpack_EOS_FocusInfoEx

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No know…

πŸ“… Published: April 17, 2026, 11:48 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

6.1

CVSS3.1

CVE-2026-40340 - libgphoto2 has OOB read in ptp_unpack_OI() in ptp-pack.c via malicious PTP ObjectInfo response

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). The function validates `len < PTP_oi_SequenceNumber` (i.e., len < 48) but subsequently accesses offsets …

πŸ“… Published: April 17, 2026, 11:45 p.m. πŸ”„ Last Modified: April 20, 2026, 7 p.m.

5.2

CVSS3.1

CVE-2026-40339 - libgphoto2 has OOB read in ptp_unpack_Sony_DPD() FormFlag parsing in ptp-pack.c

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without a prior bounds check. The standard `ptp_unp…

πŸ“… Published: April 17, 2026, 11:42 p.m. πŸ”„ Last Modified: April 20, 2026, 7 p.m.
Total resulsts: 346539
Page 141 of 34,654
Β« previous page Β» next page
Filters