5.3

CVSS4.0

CVE-2026-35023 - Wimi Teamwork On-Premises < 8.2.0 IDOR via preview.php

Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the preview.php endpoint where the item_id parameter lacks proper authorization checks. Attackers can enumerate sequential item_id values to access and retrieve image previews from other u…

📅 Published: April 8, 2026, 12:59 p.m. 🔄 Last Modified: April 8, 2026, 12:59 p.m.

7.8

CVSS3.1

CVE-2026-28261 -

Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading t…

📅 Published: April 8, 2026, 12:43 p.m. 🔄 Last Modified: April 8, 2026, 12:43 p.m.

4.4

CVSS3.1

CVE-2026-24511 -

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation of error message containing sensitive information vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to information d…

📅 Published: April 8, 2026, 12:28 p.m. 🔄 Last Modified: April 8, 2026, 12:28 p.m.

5.5

CVSS4.0

CVE-2026-5600 -

A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those …

📅 Published: April 8, 2026, 12:24 p.m. 🔄 Last Modified: April 8, 2026, 12:24 p.m.

6.6

CVSS3.1

CVE-2026-27102 -

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect privilege assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.

📅 Published: April 8, 2026, 12:11 p.m. 🔄 Last Modified: April 8, 2026, 12:11 p.m.

6.3

CVSS3.1

CVE-2026-5302 - Permissive Cross-domain Policy with Untrusted Domains in coolercontrold

CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites

📅 Published: April 8, 2026, 12:05 p.m. 🔄 Last Modified: April 8, 2026, 12:05 p.m.

5.9

CVSS3.1

CVE-2026-5300 - Missing Authentication for Critical Function in coolercontrold

Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests

📅 Published: April 8, 2026, 12:04 p.m. 🔄 Last Modified: April 8, 2026, 12:04 p.m.

7.6

CVSS3.1

CVE-2026-5301 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in coolercontr…

Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries

📅 Published: April 8, 2026, 12:04 p.m. 🔄 Last Modified: April 8, 2026, 12:04 p.m.

8.2

CVSS3.1

CVE-2026-5208 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in coole…

Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names

📅 Published: April 8, 2026, 11:36 a.m. 🔄 Last Modified: April 8, 2026, 11:36 a.m.

3.3

CVSS3.1

CVE-2026-28264 -

Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

📅 Published: April 8, 2026, 11:24 a.m. 🔄 Last Modified: April 8, 2026, 11:24 a.m.
Total resulsts: 343168
Page 2 of 34,317
« previous page » next page
Filters