7.2

CVSS3.1

CVE-2026-39387 - BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to…

πŸ“… Published: April 14, 2026, 10:56 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8

CVSS3.1

CVE-2026-35589 - nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update)

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0.0 to…

πŸ“… Published: April 14, 2026, 10:47 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

4

CVSS4.0

CVE-2026-33414 - PowerShell Command Injection in Podman HyperV Machine

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $()…

πŸ“… Published: April 14, 2026, 10:42 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

6.7

CVSS3.1

CVE-2026-40688 - Out‑of‑Bounds Write Allowing Remote Code Execution in Fortinet FortiWeb

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

πŸ“… Published: April 14, 2026, 10:35 p.m. πŸ”„ Last Modified: April 17, 2026, 3:12 p.m.

6.5

CVSS3.1

CVE-2026-35034 - Jellyfin: Potential Application DoS from excessively large SyncPlay group names

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimited size due to insufficient input validation. By …

πŸ“… Published: April 14, 2026, 10:31 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.3

CVSS4.0

CVE-2026-35033 - Jellyfin: Potential SSRF + Arbitrary file read via stream argument injection

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowerc…

πŸ“… Published: April 14, 2026, 10:28 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.6

CVSS4.0

CVE-2026-35032 - Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP …

πŸ“… Published: April 14, 2026, 10:25 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

10

CVSS3.1

CVE-2026-35031 - Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. …

πŸ“… Published: April 14, 2026, 10:18 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.1

CVSS3.1

CVE-2026-34457 - OAuth2 Proxy: Health Check User-Agent Matching Bypasses Authentication in auth_request Mode

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-…

πŸ“… Published: April 14, 2026, 10:14 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

3.5

CVSS3.1

CVE-2026-34454 - OAuth2 Proxy: Session cookie not cleared when rendering sign-in page

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 prevents OAuth2 Proxy from clearing the session cookie when rendering the sign-in page. In deployments that rely on the sign-in page as part of their logout flow, a user may be sho…

πŸ“… Published: April 14, 2026, 10:10 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 346087
Page 148 of 34,609
Β« previous page Β» next page
Filters