6.1

CVSS3.1

CVE-2026-40333 - libgphoto2 has OOB read in ptp_unpack_EOS_ImageFormat() and ptp_unpack_EOS_CustomFuncEx() due to mi…

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in ptp_unpack_EOS_events() have xsize available but never pass it, leaving bot…

📅 Published: April 17, 2026, 11:11 p.m. 🔄 Last Modified: April 22, 2026, 7:45 a.m.

7.1

CVSS4.0

CVE-2026-40480 - ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView.php page enforces canEditPerson() restrictions, the API lay…

📅 Published: April 17, 2026, 11:07 p.m. 🔄 Last Modified: April 20, 2026, 6:59 p.m.

9.1

CVSS3.1

CVE-2026-40324 - Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documents

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types…

📅 Published: April 17, 2026, 11:05 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

7.1

CVSS4.0

CVE-2026-40482 - ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}`

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.

📅 Published: April 17, 2026, 10:58 p.m. 🔄 Last Modified: April 20, 2026, 6:59 p.m.

8.9

CVSS4.0

CVE-2026-40323 - SP1 V6 Recursion Circuit Row-Count Binding Gap

SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof t…

📅 Published: April 17, 2026, 10:58 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

8.2

CVSS4.0

CVE-2026-40481 - monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validat…

monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST payloads to cause uncontrolled mem…

📅 Published: April 17, 2026, 10:54 p.m. 🔄 Last Modified: April 24, 2026, 4:57 p.m.

4.3

CVSS3.1

CVE-2026-40486 - Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, in…

Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking the isEnabled() flag on preference objects. Although the hourly_rate and internal_rate fields a…

📅 Published: April 17, 2026, 10:35 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

5.4

CVSS3.1

CVE-2026-40479 - Kimai: Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget

Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote characters. When a user's profile alias is inserted into an HTML attribute context via the team member form prototype and…

📅 Published: April 17, 2026, 10:31 p.m. 🔄 Last Modified: April 18, 2026, 9 a.m.

6.4

CVSS3.1

CVE-2026-2434 - Pz-LinkCard <= 2.5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Att…

The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-le…

📅 Published: April 17, 2026, 10:27 p.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

9.1

CVSS3.1

CVE-2026-40478 - Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly ne…

📅 Published: April 17, 2026, 9:57 p.m. 🔄 Last Modified: April 24, 2026, 4:58 p.m.
Total resulsts: 346571
Page 146 of 34,658
« previous page » next page
Filters