8.1

CVSS3.1

CVE-2026-40600 - Chartbrew: Incorrect Access Control in project share policy routes via unbound policy_id

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows authenticated users with access to one project to update or delete a SharePolicy record that belongs to a different project. The affected…

📅 Published: April 30, 2026, 6:22 p.m. 🔄 Last Modified: April 30, 2026, 9 p.m.

7.5

CVSS3.1

CVE-2026-40595 - Chartbrew: Incorrect Access Control in public chart and export routes via missing onReport and Shar…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only verify project-level public access and, for exports, a team-level export toggle. The …

📅 Published: April 30, 2026, 6:21 p.m. 🔄 Last Modified: April 30, 2026, 8:30 p.m.

6.5

CVSS3.1

CVE-2026-35514 - Unauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions in Chartbrew

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint…

📅 Published: April 30, 2026, 6:21 p.m. 🔄 Last Modified: May 1, 2026, 4:38 p.m.

8.1

CVSS3.1

CVE-2026-40904 - Chartbrew: Incorrect Access Control in dataset and dataRequest routes via team-scoped permission ch…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes multiple dataset and dataRequest endpoints that authorize low-privileged project members at the team level instead of binding the reques…

📅 Published: April 30, 2026, 6:20 p.m. 🔄 Last Modified: April 30, 2026, 8:30 p.m.

8.9

CVSS4.0

CVE-2026-32148 - Lockfile checksums not verified in Hex allows dependency integrity bypass

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in the mix.lock file to ensure reproducible and integrity-checked builds. However, Hex.…

📅 Published: April 30, 2026, 6:17 p.m. 🔄 Last Modified: May 5, 2026, 2:16 a.m.

3.7

CVSS3.1

CVE-2026-3832 - Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp r…

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabl…

📅 Published: April 30, 2026, 5:29 p.m. 🔄 Last Modified: May 3, 2026, 7:27 p.m.

7.5

CVSS3.1

CVE-2026-33845 - Gnutls: gnutls: denial of service via dtls zero-length fragment

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.

📅 Published: April 30, 2026, 5:28 p.m. 🔄 Last Modified: May 5, 2026, 3:03 a.m.

6.5

CVSS3.1

CVE-2026-3833 - Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting…

📅 Published: April 30, 2026, 5:26 p.m. 🔄 Last Modified: May 7, 2026, 2:09 a.m.

8.7

CVSS4.0

CVE-2025-51846 - CryptPad unbounded WebSocket frame flood

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.

📅 Published: April 30, 2026, 4:35 p.m. 🔄 Last Modified: May 4, 2026, 4:52 p.m.

8.7

CVSS4.0

CVE-2022-50992 - Weaver E-cology 9.5 Unauthenticated Arbitrary File Read via XmlRpcServlet

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowServ…

📅 Published: April 30, 2026, 4:09 p.m. 🔄 Last Modified: May 1, 2026, 8:21 a.m.
Total resulsts: 349182
Page 186 of 34,919
« previous page » next page
Filters