7.5

CVSS3.1

CVE-2026-24006 - Seroval affected by Denial of Service via Deeply Nested Objects

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serializaโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

9.1

CVSS3.1

CVE-2026-24002 - pyodide sandbox option is insecure

Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working with untrusted spreadsheets. One such method runs them in pyodide, but pyodide on node does not have a useful sandbox barโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:26 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

2.7

CVSS4.0

CVE-2026-24001 - jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause the `parsePatch` method to enter an infinite loop. It then consumes mโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:23 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:30 p.m.

5.9

CVSS3.1

CVE-2026-23992 - go-tuf improperly validates the configured threshold for delegations

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:20 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

5.9

CVSS3.1

CVE-2026-23991 - go-tuf affected by client DoS via malformed server response

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial ofโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:16 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

9.1

CVSS3.1

CVE-2026-23966 - sm-crypto Affected by Private Key Recovery in SM2-PKE

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can fulโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:06 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

7.5

CVSS3.1

CVE-2026-23965 - sm-crypto Affected by Signature Forgery in SM2-DSA

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature forgery vulnerability exists in the SM2 signature verification logic of sm-crypto prior to version 0.4.0. Under default configurations, an attacker can forge valid signatures for arbโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:05 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

7.5

CVSS3.1

CVE-2026-23967 - sm-crypto Affected by Signature Malleability in SM2-DSA

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library prior to version 0.3.14. An attacker can derive a new valid signature for a previouโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:59 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

6.9

CVSS4.0

CVE-2026-23959 - CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier

CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` within the CoreShop admin panel. The affected endpoint improperly interpolates user-supplied input into a SQL query, leadingโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:57 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

6.5

CVSS3.1

CVE-2026-23964 - Mastodon has insufficient access control to push notification settings

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessing or obtaining the โ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:55 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.
Total resulsts: 346172
Page 1731 of 34,618
ยซ previous page ยป next page
Filters