9.6

CVSS3.1

CVE-2026-40471 - Hackage CSRF vulnerability

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abus…

📅 Published: April 23, 2026, 2:56 p.m. 🔄 Last Modified: April 28, 2026, 9:25 a.m.

6

CVSS4.0

CVE-2026-41240 - DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fi…

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The same fix was not ap…

📅 Published: April 23, 2026, 2:54 p.m. 🔄 Last Modified: April 28, 2026, 1:45 a.m.

9.9

CVSS3.1

CVE-2026-40470 - Hackage package and doc upload stored XSS vulnerability

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the main hackage.haskell.org domain. As a consequence, when a user with latent HTTP credentials browses…

📅 Published: April 23, 2026, 2:53 p.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.

6.8

CVSS3.1

CVE-2026-41239 - DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS …

📅 Published: April 23, 2026, 2:47 p.m. 🔄 Last Modified: April 25, 2026, 1:21 a.m.

9.3

CVSS4.0

CVE-2026-23751 - Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unaut…

📅 Published: April 23, 2026, 2:46 p.m. 🔄 Last Modified: April 25, 2026, 1:20 a.m.

6.9

CVSS3.1

CVE-2026-41238 - DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prot…

📅 Published: April 23, 2026, 2:43 p.m. 🔄 Last Modified: April 23, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-62373 - Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integra…

📅 Published: April 23, 2026, 2:40 p.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.

7.8

CVSS3.1

CVE-2026-34003 - Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory…

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, lea…

📅 Published: April 23, 2026, 2:18 p.m. 🔄 Last Modified: May 4, 2026, 12:38 p.m.

7.8

CVSS3.1

CVE-2026-34001 - Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential me…

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially…

📅 Published: April 23, 2026, 2:14 p.m. 🔄 Last Modified: May 4, 2026, 12:38 p.m.

7.8

CVSS3.1

CVE-2026-33999 - Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map ha…

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service…

📅 Published: April 23, 2026, 2:11 p.m. 🔄 Last Modified: May 4, 2026, 12:38 p.m.
Total resulsts: 347933
Page 178 of 34,794
« previous page » next page
Filters