8.8

CVSS3.1

CVE-2026-40352 - FastGPT: NoSQL Injection in updatePasswordByOld Leads to Account Takeover

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged โ€ฆ

๐Ÿ“… Published: April 17, 2026, 9:09 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:03 p.m.

6.9

CVSS4.0

CVE-2026-40306 - DNN has same HostGUID for all new installs

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue.

๐Ÿ“… Published: April 17, 2026, 9:09 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 2:29 p.m.

4.3

CVSS3.1

CVE-2026-40305 - DNN has Force Friend Request Acceptance

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2โ€ฆ

๐Ÿ“… Published: April 17, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 2:40 p.m.

9.8

CVSS3.1

CVE-2026-40351 - FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL inโ€ฆ

๐Ÿ“… Published: April 17, 2026, 9:05 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:03 p.m.

5.3

CVSS3.1

CVE-2026-40304 - zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontendโ€ฆ

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NULL (the marker for admin-created global frontends), the condiโ€ฆ

๐Ÿ“… Published: April 17, 2026, 9:04 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 6:33 p.m.

7.5

CVSS3.1

CVE-2026-40303 - zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, count) with no upper bound before any token validation occurs. The function is reached on every requestโ€ฆ

๐Ÿ“… Published: April 17, 2026, 9:01 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 6:33 p.m.

8.1

CVSS3.1

CVE-2026-40196 - HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the aโ€ฆ

๐Ÿ“… Published: April 17, 2026, 9:01 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 2:23 p.m.

6.1

CVSS3.1

CVE-2026-40302 - zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/template. The GitHub OAuth callback handlers in both publicProxy and dynamicProxy embed the attackerโ€ฆ

๐Ÿ“… Published: April 17, 2026, 8:56 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 6:32 p.m.

5.4

CVSS3.1

CVE-2026-40155 - Auth0 Next.js SDK has Improper Proxy Cache Lookup

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users are affected if theโ€ฆ

๐Ÿ“… Published: April 17, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:03 p.m.

4.7

CVSS3.1

CVE-2026-40301 - rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import direcโ€ฆ

DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to attaโ€ฆ

๐Ÿ“… Published: April 17, 2026, 8:51 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:03 p.m.
Total resulsts: 346555
Page 146 of 34,656
ยซ previous page ยป next page
Filters