8.5

CVSS3.1

CVE-2026-39942 - Directus has a Path Traversal and Broken Access Control in File Management API

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content …

📅 Published: April 9, 2026, 4:07 p.m. 🔄 Last Modified: April 14, 2026, 5:36 p.m.

5.5

CVSS3.1

CVE-2026-39856 - osslsigncode has an Out-of-Bounds Read via Unvalidated Section Bounds in PE Page Hash Calculation

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When processing PE sections for page hashing, the function use…

📅 Published: April 9, 2026, 4:03 p.m. 🔄 Last Modified: April 17, 2026, 7:59 p.m.

5.5

CVSS3.1

CVE-2026-39855 - osslsigncode has an Integer Underflow in PE Page Hash Calculation Can Cause Out-of-Bounds Read

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When page hash processing is performed on a PE file, the functi…

📅 Published: April 9, 2026, 3:58 p.m. 🔄 Last Modified: April 17, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2026-40046 - Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT co…

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versi…

📅 Published: April 9, 2026, 3:58 p.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

4.3

CVSS3.1

CVE-2026-33005 - Apache OpenMeetings: Insufficient checks in FileWebService

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields…

📅 Published: April 9, 2026, 3:52 p.m. 🔄 Last Modified: April 15, 2026, 3:27 p.m.

7.5

CVSS3.1

CVE-2026-33266 - Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logg…

📅 Published: April 9, 2026, 3:52 p.m. 🔄 Last Modified: April 15, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2026-34020 - Apache OpenMeetings: Login Credentials Passed via GET Query Parameters

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 be…

📅 Published: April 9, 2026, 3:52 p.m. 🔄 Last Modified: April 15, 2026, 3:21 p.m.

7.8

CVSS3.1

CVE-2026-39853 - osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7 signature, the code copies the digest value from a parsed SpcIndirectDat…

📅 Published: April 9, 2026, 3:50 p.m. 🔄 Last Modified: April 17, 2026, 8:03 p.m.

7.7

CVSS3.1

CVE-2026-39843 - Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-Side Request Forgery when a normal html page contains a link tag with an href that redirects to a private IP address is…

📅 Published: April 9, 2026, 3:43 p.m. 🔄 Last Modified: April 17, 2026, 8:08 p.m.

5.3

CVSS4.0

CVE-2026-39941 - ChurchCRM has an XSS vulnerability

ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and EDesc parameters in EditEventAttendees.php to be rendered in a page without proper output encoding, enabling arbitrary JavaScript execution in victims' …

📅 Published: April 9, 2026, 3:38 p.m. 🔄 Last Modified: April 14, 2026, 4:36 p.m.
Total resulsts: 345275
Page 178 of 34,528
« previous page » next page
Filters