3.5

CVSS3.1

CVE-2026-40341 - libgphoto2 has an OOB Read in ptp_unpack_EOS_FocusInfoEx

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input from untrusted USB devices. Commit c385b34af260595dfbb5f9329526be5158985987 contains a patch. No know…

πŸ“… Published: April 17, 2026, 11:48 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

6.1

CVSS3.1

CVE-2026-40340 - libgphoto2 has OOB read in ptp_unpack_OI() in ptp-pack.c via malicious PTP ObjectInfo response

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). The function validates `len < PTP_oi_SequenceNumber` (i.e., len < 48) but subsequently accesses offsets …

πŸ“… Published: April 17, 2026, 11:45 p.m. πŸ”„ Last Modified: April 20, 2026, 7 p.m.

5.2

CVSS3.1

CVE-2026-40339 - libgphoto2 has OOB read in ptp_unpack_Sony_DPD() FormFlag parsing in ptp-pack.c

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The function reads the FormFlag byte via `dtoh8o(data, *poffset)` without a prior bounds check. The standard `ptp_unp…

πŸ“… Published: April 17, 2026, 11:42 p.m. πŸ”„ Last Modified: April 20, 2026, 7 p.m.

5.2

CVSS3.1

CVE-2026-40338 - libgphoto2 has OOB read in ptp_unpack_Sony_DPD() enumeration count parsing in ptp-pack.c

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` withou…

πŸ“… Published: April 17, 2026, 11:40 p.m. πŸ”„ Last Modified: April 20, 2026, 7 p.m.

5.3

CVSS3.1

CVE-2026-40485 - ChurchCRM: Username Enumeration via Differential Response in Public Login API

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a username exists: 404 for non-existent users and 401 for valid users with incorrect passwords. An un…

πŸ“… Published: April 17, 2026, 11:29 p.m. πŸ”„ Last Modified: April 20, 2026, 6:59 p.m.

2.4

CVSS3.1

CVE-2026-40336 - libgphoto2 has memory leak in ptp_unpack_Sony_DPD() secondary enumeration list in ptp-pack.c

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When processing a secondary enumeration list (introduced in 2024+ Sony cameras), the function overwrites dpd->FORM.Enum.…

πŸ“… Published: April 17, 2026, 11:27 p.m. πŸ”„ Last Modified: April 22, 2026, 3:45 a.m.

7.5

CVSS3.1

CVE-2026-2262 - Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information Exposure via REST API

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`…

πŸ“… Published: April 17, 2026, 11:26 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

9.1

CVSS3.1

CVE-2026-40484 - ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Database Restore …

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directory into the web-accessible document root using recursiveCopyDirectory(), which performs no file ext…

πŸ“… Published: April 17, 2026, 11:25 p.m. πŸ”„ Last Modified: April 20, 2026, 6:59 p.m.

5.4

CVSS3.1

CVE-2026-40483 - ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via htmlspecialchars(). An authenticated user with Finance permissions can inject HTML attribute-breaking ch…

πŸ“… Published: April 17, 2026, 11:20 p.m. πŸ”„ Last Modified: April 18, 2026, 12:16 a.m.

5.2

CVSS3.1

CVE-2026-40335 - libgphoto2 has OOB read in ptp_unpack_DPV() UINT128/INT128 handling in ptp-pack.c

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The UINT128 and INT128 cases advance `*offset += 16` without verifying that 16 bytes remain in the buffer. The entry …

πŸ“… Published: April 17, 2026, 11:19 p.m. πŸ”„ Last Modified: April 20, 2026, 7 p.m.
Total resulsts: 346934
Page 181 of 34,694
Β« previous page Β» next page
Filters