7.5

CVSS3.1

CVE-2026-35465 - SecureDrop Client has path injection in read_gzip_header_filename()

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper fileโ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:41 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:16 a.m.

9

CVSS3.1

CVE-2026-40572 - NovumOS has Arbitrary Memory Mapping via Syscall 15 (MemoryMapRange)

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their address space without validating against forbidden regions, including critical kerโ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:16 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:16 a.m.

9.4

CVSS3.1

CVE-2026-40317 - NovumOS has Privilege Escalation in the Syscall Interface

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allowing any Ring 3 user-mode process to jump to kernel addresses and execute arbitrโ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:12 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:16 a.m.

8.8

CVSS3.1

CVE-2026-40350 - Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users โ€ฆ

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the route deโ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:07 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:16 a.m.

8.8

CVSS3.1

CVE-2026-40349 - Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Seโ€ฆ

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a useโ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:05 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 a.m.

4.8

CVSS3.1

CVE-2026-40593 - ChurchCRM: Stored XSS in UserEditor.php via Login Name Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applying htmlspecialchars(). An administrator can save a username containing HTML attribute-breaking characโ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:02 a.m.

7.7

CVSS3.1

CVE-2026-40348 - Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Proโ€ฆ

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoint accepts a user-controlled URL, appends โ€ฆ

๐Ÿ“… Published: April 18, 2026, 12:01 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 a.m.

5.3

CVSS3.1

CVE-2026-40347 - Python-Multipart affected by Denial of Service via large multipart preamble or epilogue data

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candiโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:56 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 a.m.

6.4

CVSS4.0

CVE-2026-40346 - NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request action plugin make server-side HTTP requests to user-provided URLs without any SSRF protection. An autโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:54 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:54 p.m.

8.1

CVSS3.1

CVE-2026-40581 - ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Data Deletion

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records and all associated data via a plain GET request with no CSRF token validation. An attacker can craft aโ€ฆ

๐Ÿ“… Published: April 17, 2026, 11:51 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:51 p.m.
Total resulsts: 345119
Page 2 of 34,512
ยซ previous page ยป next page
Filters