9.1

CVSS3.1

CVE-2026-40484 - ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore โ€ฆ

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using recursiveCopyDirectory(), which performs no file extโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:25 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:59 p.m.

5.4

CVSS3.1

CVE-2026-40483 - ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user with Finance permissions can inject HTML attribute-breaking chโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:20 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:16 a.m.

5.2

CVSS3.1

CVE-2026-40335 - libgphoto2 has OOB read in ptp_unpack_DPV() UINT128/INT128 handling in ptp-pack.c

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622โ€“629). The UINT128 and INT128 cases advance `*offset += 16` without verifying that 16 bytes remain in the buffer. The entry โ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:19 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7 p.m.

3.5

CVSS3.1

CVE-2026-40334 - libgphoto2 missing null termination in ptp_unpack_Canon_FE() filename buffer in ptp-pack.c

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line 1377). The function copies a filename into a 13-byte buffer using strncpy without explicitly null-terminating the resโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:16 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7 p.m.

9.1

CVSS4.0

CVE-2026-40582 - ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Account Lockoโ€ฆ

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, bypassing the normal authentication flow that enforces account lockout and two-factor authentication chโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:16 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:59 p.m.

6.1

CVSS3.1

CVE-2026-40333 - libgphoto2 has OOB read in ptp_unpack_EOS_ImageFormat() and ptp_unpack_EOS_CustomFuncEx() due to miโ€ฆ

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no length parameter, performing unbounded reads. Their callers in ptp_unpack_EOS_events() have xsize available but never pass it, leaving botโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:11 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 7:45 a.m.

7.1

CVSS4.0

CVE-2026-40480 - ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization checks. Although the legacy PersonView.php page enforces canEditPerson() restrictions, the API layโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:07 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:59 p.m.

9.1

CVSS3.1

CVE-2026-40324 - Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documents

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list typesโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:05 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:03 p.m.

7.1

CVSS4.0

CVE-2026-40482 - ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}`

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue has been fixed in version 7.2.0.

๐Ÿ“… Published: April 17, 2026, 10:58 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 6:59 p.m.

8.9

CVSS4.0

CVE-2026-40323 - SP1 V6 Recursion Circuit Row-Count Binding Gap

SP1 is a zeroโ€‘knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof tโ€ฆ

๐Ÿ“… Published: April 17, 2026, 10:58 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:03 p.m.
Total resulsts: 346616
Page 150 of 34,662
ยซ previous page ยป next page
Filters