5.3

CVSS3.1

CVE-2026-41182 - LangSmith SDK: Streaming token events bypass output redaction

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When…

πŸ“… Published: April 23, 2026, 12:14 a.m. πŸ”„ Last Modified: April 28, 2026, midnight

7.5

CVSS3.1

CVE-2026-41180 - PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code executi…

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.params.uploadId`. In dep…

πŸ“… Published: April 23, 2026, 12:10 a.m. πŸ”„ Last Modified: April 27, 2026, 10:30 p.m.

6.9

CVSS4.0

CVE-2026-41243 - OpenLearn's pending forum posts remain publicly readable by direct ID when moderation mode is enabl…

OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the direct post-read procedure still returns the full post to anyone with the post UUID. Commit 844b…

πŸ“… Published: April 23, 2026, 12:09 a.m. πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

9.2

CVSS4.0

CVE-2026-41179 - RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and loca…

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. Because `rc.G…

πŸ“… Published: April 23, 2026, 12:03 a.m. πŸ”„ Last Modified: April 25, 2026, 3:55 a.m.

8.4

CVSS4.0

CVE-2026-32679 -

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at t…

πŸ“… Published: April 23, 2026, 12:02 a.m. πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

8.7

CVSS4.0

CVE-2026-40062 -

A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system.

πŸ“… Published: April 23, 2026, 12:01 a.m. πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

6.3

CVSS4.0

CVE-2026-6878 - ByteDance verl grader.py math_equal sandbox

A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be d…

πŸ“… Published: April 23, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

6.5

CVSS3.1

CVE-2026-31159 -

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the password parameter to /cgi-bin/cstecgi.cgi.

πŸ“… Published: April 23, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:13 p.m.

7.3

CVSS3.1

CVE-2025-70994 -

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic challenge-response mechanisms. This is vulnerable to signal fo…

πŸ“… Published: April 23, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

9.8

CVSS3.1

CVE-2026-31175 -

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi.

πŸ“… Published: April 23, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:12 p.m.
Total resulsts: 347827
Page 173 of 34,783
Β« previous page Β» next page
Filters