8.8

CVSS3.1

CVE-2026-29648 - Privilege Escalation via Improper CSRs Access in OpenXiangShan NEMU

In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privileged code may read or write these CSRs without the required exception, potentially bypassing intended state-enable based isolation controls …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

7.5

CVSS3.1

CVE-2026-29645 -

NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly validate the funct3 field when decoding vsetvli/vsetivli/vsetvl, allowing certain invalid OP-V instruction encodings to be misinterpreted …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

5.3

CVSS3.1

CVE-2026-26399 -

A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it is stored in a global timer handle registry. After the functi…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 9:26 a.m.

5.4

CVSS3.1

CVE-2026-39112 -

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisito…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 8:21 p.m.

7.8

CVSS3.1

CVE-2026-30266 - Local Arbitrary Code Execution via Insecure Permissions in DeepCool DeepCreative

Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 4:42 p.m.

4.3

CVSS3.1

CVE-2026-41285 -

In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expression with no preceding check for whether nd_opt_len is zero.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 4:30 p.m.

5.3

CVSS4.0

CVE-2026-6586 - TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. T…

πŸ“… Published: April 19, 2026, 11:45 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6585 - TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation author…

A vulnerability was determined in TransformerOptimus SuperAGI up to 0.0.14. This issue affects the function update_organisation of the file superagi/controllers/organisation.py of the component Organisation Update Endpoint. This manipulation of the argument organisation_id causes authorization bypa…

πŸ“… Published: April 19, 2026, 11:30 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6584 - TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization

A vulnerability was found in TransformerOptimus SuperAGI up to 0.0.14. This vulnerability affects the function update_user of the file superagi/controllers/user.py of the component User Update Endpoint. The manipulation of the argument user_id results in authorization bypass. The attack may be perf…

πŸ“… Published: April 19, 2026, 11:15 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.

5.3

CVSS4.0

CVE-2026-6583 - TransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization

A vulnerability has been found in TransformerOptimus SuperAGI up to 0.0.14. This affects the function delete_api_key/edit_api_key of the file superagi/controllers/api_key.py of the component API Key Management Endpoint. The manipulation leads to authorization bypass. The attack is possible to be ca…

πŸ“… Published: April 19, 2026, 11 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.
Total resulsts: 347055
Page 186 of 34,706
Β« previous page Β» next page
Filters