8.8

CVSS3.1

CVE-2026-41208 - Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to …

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server…

📅 Published: April 23, 2026, 12:47 a.m. 🔄 Last Modified: April 27, 2026, 3:14 p.m.

6.9

CVSS4.0

CVE-2026-41206 - PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.valid…

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis to prevent dangerous code from being loaded as plugins. Prior to version 0.1.8, the blocklist implemented in…

📅 Published: April 23, 2026, 12:42 a.m. 🔄 Last Modified: April 28, 2026, 2 a.m.

8.5

CVSS4.0

CVE-2026-41200 - STIG Manager has reflected XSS vulnerability in the Web App

STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in `src/init.js` and `public…

📅 Published: April 23, 2026, 12:40 a.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.

9.3

CVSS4.0

CVE-2026-41197 - Brillig: Heap corruption in foreign call results with nested tuple arrays

Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can invoke external functions through foreign calls. When compiling to Brillig bytecode, the SSA instruct…

📅 Published: April 23, 2026, 12:35 a.m. 🔄 Last Modified: April 25, 2026, 3:55 a.m.

9

CVSS4.0

CVE-2026-41196 - Luanti has a mod security sandbox escape

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. This applies to the se…

📅 Published: April 23, 2026, 12:28 a.m. 🔄 Last Modified: April 28, 2026, 9 a.m.

5.3

CVSS3.1

CVE-2026-41182 - LangSmith SDK: Streaming token events bypass output redaction

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When…

📅 Published: April 23, 2026, 12:14 a.m. 🔄 Last Modified: April 28, 2026, midnight

7.5

CVSS3.1

CVE-2026-41180 - PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code executi…

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.params.uploadId`. In dep…

📅 Published: April 23, 2026, 12:10 a.m. 🔄 Last Modified: April 27, 2026, 10:30 p.m.

6.9

CVSS4.0

CVE-2026-41243 - OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabl…

OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still returns the full post to anyone with the post UUID. Commit 844b…

📅 Published: April 23, 2026, 12:09 a.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.

9.2

CVSS4.0

CVE-2026-41179 - RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and loca…

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. Because `rc.G…

📅 Published: April 23, 2026, 12:03 a.m. 🔄 Last Modified: April 25, 2026, 3:55 a.m.

8.4

CVSS4.0

CVE-2026-32679 -

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at t…

📅 Published: April 23, 2026, 12:02 a.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.
Total resulsts: 347821
Page 172 of 34,783
« previous page » next page
Filters