9.8

CVSS3.1

CVE-2026-40351 - FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL in…

📅 Published: April 17, 2026, 9:05 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

5.3

CVSS3.1

CVE-2026-40304 - zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend…

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NULL (the marker for admin-created global frontends), the condi…

📅 Published: April 17, 2026, 9:04 p.m. 🔄 Last Modified: April 23, 2026, 6:33 p.m.

7.5

CVSS3.1

CVE-2026-40303 - zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, count) with no upper bound before any token validation occurs. The function is reached on every request…

📅 Published: April 17, 2026, 9:01 p.m. 🔄 Last Modified: April 23, 2026, 6:33 p.m.

8.1

CVSS3.1

CVE-2026-40196 - HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the a…

📅 Published: April 17, 2026, 9:01 p.m. 🔄 Last Modified: April 24, 2026, 2:23 p.m.

6.1

CVSS3.1

CVE-2026-40302 - zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/template. The GitHub OAuth callback handlers in both publicProxy and dynamicProxy embed the attacker…

📅 Published: April 17, 2026, 8:56 p.m. 🔄 Last Modified: April 23, 2026, 6:32 p.m.

5.4

CVSS3.1

CVE-2026-40155 - Auth0 Next.js SDK has Improper Proxy Cache Lookup

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results. Users are affected if the…

📅 Published: April 17, 2026, 8:54 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

4.7

CVSS3.1

CVE-2026-40301 - rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import direc…

DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. CSS url() references and @import rules pass through unfiltered, causing the browser to issue HTTP requests to atta…

📅 Published: April 17, 2026, 8:51 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

6.9

CVSS4.0

CVE-2026-40299 - next-intl has an open redirect vulnerability

next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//`…

📅 Published: April 17, 2026, 8:49 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

6.5

CVSS3.1

CVE-2026-40293 - OpenFGA Playground Preshared Key Exposure

OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint…

📅 Published: April 17, 2026, 8:47 p.m. 🔄 Last Modified: April 22, 2026, 6:15 a.m.

5.4

CVSS4.0

CVE-2026-35603 - Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windo…

Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating directory ownership or access permissions. Because the ProgramData directory is writable by…

📅 Published: April 17, 2026, 8:38 p.m. 🔄 Last Modified: April 22, 2026, 6:45 p.m.
Total resulsts: 346560
Page 147 of 34,656
« previous page » next page
Filters