5.3

CVSS4.0

CVE-2026-6590 - ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal

A vulnerability was detected in ComfyUI up to 0.13.0. This impacts the function get_model_preview of the file app/model_manager.py of the component Model Preview Endpoint. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used. The…

πŸ“… Published: April 20, 2026, 12:45 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6589 - ComfyUI server.py create_origin_only_middleware cross-site request forgery

A security vulnerability has been detected in ComfyUI up to 0.13.0. This affects the function create_origin_only_middleware of the file server.py. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The…

πŸ“… Published: April 20, 2026, 12:30 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

6.9

CVSS4.0

CVE-2026-6588 - serge-chat serge Model API Endpoint model.py delete_model missing authentication

A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched re…

πŸ“… Published: April 20, 2026, 12:15 a.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6587 - vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argu…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

6.6

CVSS3.1

CVE-2026-31430 - X.509: Fix out-of-bounds access when parsing extensions

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty Basic Constraints or Key Usage extension because the first byte of the extension is read before che…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:17 p.m.

7.5

CVSS3.1

CVE-2026-39111 - SQL Injection Vulnerability in Apartment Visitors Management System Forgot Password Page

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 12:15 a.m.

0.0

CVE-2026-39112 -

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisito…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 5:20 p.m.

9.4

CVSS3.1

CVE-2026-39109 -

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 12:15 a.m.

8.8

CVSS3.1

CVE-2026-29648 - Privilege Escalation via Improper CSRs Access in OpenXiangShan NEMU

In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privileged code may read or write these CSRs without the required exception, potentially bypassing intended state-enable based isolation controls …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 7:45 a.m.

6.5

CVSS3.1

CVE-2025-66954 - Unauthenticated Username Enumeration via /nasapi Endpoint in Buffalo Link Station Firmware 1.85-0.01

A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 4 p.m.
Total resulsts: 346768
Page 156 of 34,677
Β« previous page Β» next page
Filters