6.9

CVSS4.0

CVE-2026-24043 - jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function allows users to inject arbitrary XML. If given the possibility to pass unsanitized input to the addMetadata method, a user can inject arbitrary XMP metadata into the gen…

📅 Published: Feb. 2, 2026, 8:34 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

8.7

CVSS4.0

CVE-2026-24133 - jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful BMP file that results in ou…

📅 Published: Feb. 2, 2026, 8:32 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

8.1

CVSS3.1

CVE-2026-24737 - jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties…

📅 Published: Feb. 2, 2026, 8:29 p.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

8

CVSS3.1

CVE-2026-23997 - FacturaScripts has a Stored Cross-Site Scripting (XSS) in "Observations" field via History View

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity e…

📅 Published: Feb. 2, 2026, 8:19 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

7.3

CVSS4.0

CVE-2026-0924 - BuhoCleaner 1.15.2 - Local Privilege Escalation via PID reuse attack

BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoCleaner: 1.15.2.

📅 Published: Feb. 2, 2026, 8:18 p.m. 🔄 Last Modified: April 20, 2026, 2:12 p.m.

8.2

CVSS4.0

CVE-2026-1778 - TLS disabled by default in select aws/sagemaker-python-sdk configurations

Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed.

📅 Published: Feb. 2, 2026, 8:14 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

8.5

CVSS4.0

CVE-2026-1777 - Cleartext transmission of sensitive materials in aws/sagemaker-python-sdk

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training Jobs S3 output locatio…

📅 Published: Feb. 2, 2026, 8:10 p.m. 🔄 Last Modified: April 18, 2026, 2:30 p.m.

4.6

CVSS3.1

CVE-2026-24007 - Tuleap is missing CSRF protection in the Overview inconsistent items

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This…

📅 Published: Feb. 2, 2026, 7:52 p.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

7

CVSS3.1

CVE-2026-24051 - OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search pa…

📅 Published: Feb. 2, 2026, 7:49 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

9.3

CVSS4.0

CVE-2026-24471 - Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('…

continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server to sign an arbitrary event upon user interaction. Upon a user account leaving a room (rejecting an invite), joining a room or knocking on a room, the v…

📅 Published: Feb. 2, 2026, 6:56 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.
Total resulsts: 347634
Page 1702 of 34,764
« previous page » next page
Filters