8.7

CVSS4.0

CVE-2026-1330 - HAMASTAR Technology|MeetingHub - Arbitrary File Read

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

📅 Published: Jan. 22, 2026, 8:29 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

4.3

CVSS3.1

CVE-2026-24332 - Discord Invisible Mode Information Disclosure via WebSocket Presence API

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presenc…

📅 Published: Jan. 22, 2026, 8:10 a.m. 🔄 Last Modified: April 18, 2026, 3:30 p.m.

9.8

CVSS3.1

CVE-2026-0920 - LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor …

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for unauthent…

📅 Published: Jan. 22, 2026, 6:47 a.m. 🔄 Last Modified: April 15, 2026, 7:15 p.m.

6.8

CVSS3.1

CVE-2025-71176 - pytest: pytest: Denial of Service or Privilege Escalation via insecure temporary directory handling

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

📅 Published: Jan. 22, 2026, 4:59 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2026-24049 - wheel Allows Arbitrary File Permission Modification via Path Traversal

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the arch…

📅 Published: Jan. 22, 2026, 4:02 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

9.4

CVSS3.1

CVE-2026-24042 - Appsmith public apps can execute unpublished actions (viewMode confusion)

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticated users to execute unpublished (edit-mode) actions by sending viewMode=false (or omitting it) to POST /api/v1/actions/execute. This bypasses the exp…

📅 Published: Jan. 22, 2026, 3:52 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

4.3

CVSS3.1

CVE-2026-24039 - Horilla's Improper Access Control Allows Employees to Auto-Approve Documents

Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employees to self-approve documents they have uploaded. The document-approval UI is intended to be restricted to administrator or high-privilege roles only; …

📅 Published: Jan. 22, 2026, 3:43 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

8.1

CVSS3.1

CVE-2026-24038 - Horilla HR has 2FA Bypass through its OTP Handling Logic

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP expires, the server returns None, and if an attacker omits the otp field from their POST request, the user-supplied OTP i…

📅 Published: Jan. 22, 2026, 3:39 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

4.8

CVSS3.1

CVE-2026-24037 - Horilla HRM has XSS Bypass through Project Name

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching input against a set of regex patterns. However, the regexes are incomplete and context-agnostic, making them easy to bypass. Attackers are able to re…

📅 Published: Jan. 22, 2026, 3:31 a.m. 🔄 Last Modified: April 18, 2026, 3:30 p.m.

5.3

CVSS3.1

CVE-2026-24036 - Horilla Exposes Unpublished Job Disclosures through Unauthenticated API

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recruitment/recruitment-details// endpoint without authentication. The response includes draft job titles, descriptions and application link allowing unau…

📅 Published: Jan. 22, 2026, 3:21 a.m. 🔄 Last Modified: April 18, 2026, 3:30 p.m.
Total resulsts: 349182
Page 2030 of 34,919
« previous page » next page
Filters