6.3

CVSS4.0

CVE-2026-24055 - Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking

Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId provided by the client without authentication or authorization. The projectId is preserved throughout the OAuth flow, a…

πŸ“… Published: Jan. 22, 2026, 3:07 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.

4.3

CVSS3.1

CVE-2026-24035 - Horilla has Improper Access Control Issue that Allows Unauthorized Document Upload on Behalf of Ano…

Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exists in Horilla HR Software starting in version 1.4.0 and prior to version 1.5.0, allowing any authenticated employee to upload documents on behalf of another employee without prope…

πŸ“… Published: Jan. 22, 2026, 2:43 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.

5.4

CVSS3.1

CVE-2026-24034 - Horilla has File Upload XSS

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be triggered because the extension and content-type are not checked during the profile photo update step. Version 1.5.0 fixes the issue.

πŸ“… Published: Jan. 22, 2026, 2:41 a.m. πŸ”„ Last Modified: April 18, 2026, 3:30 p.m.

8.0

CVSS3.1

CVE-2026-24010 - Horilla has HTML Injection Issue that, with Phishing, Leads to Account Takeover

Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Social Engineering, allows authenticated users to deploy phishing attacks. By uploading a malicious HTML file disguised as a profile picture, an attacker …

πŸ“… Published: Jan. 22, 2026, 2:37 a.m. πŸ”„ Last Modified: April 18, 2026, 3:30 p.m.

7.5

CVSS3.1

CVE-2026-24006 - Seroval affected by Denial of Service via Deeply Nested Objects

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serializa…

πŸ“… Published: Jan. 22, 2026, 2:32 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.

9.1

CVSS3.1

CVE-2026-24002 - pyodide sandbox option is insecure

Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working with untrusted spreadsheets. One such method runs them in pyodide, but pyodide on node does not have a useful sandbox bar…

πŸ“… Published: Jan. 22, 2026, 2:26 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.

2.7

CVSS4.0

CVE-2026-24001 - jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause the `parsePatch` method to enter an infinite loop. It then consumes m…

πŸ“… Published: Jan. 22, 2026, 2:23 a.m. πŸ”„ Last Modified: April 18, 2026, 3:30 p.m.

5.9

CVSS3.1

CVE-2026-23992 - go-tuf improperly validates the configured threshold for delegations

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauth…

πŸ“… Published: Jan. 22, 2026, 2:20 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.

5.9

CVSS3.1

CVE-2026-23991 - go-tuf affected by client DoS via malformed server response

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of…

πŸ“… Published: Jan. 22, 2026, 2:16 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.

9.1

CVSS3.1

CVE-2026-23966 - sm-crypto Affected by Private Key Recovery in SM2-PKE

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can ful…

πŸ“… Published: Jan. 22, 2026, 2:06 a.m. πŸ”„ Last Modified: April 18, 2026, 4 a.m.
Total resulsts: 349182
Page 2031 of 34,919
Β« previous page Β» next page
Filters