5.3

CVSS3.1

CVE-2026-23990 - Flux Operator Web UI Impersonation Bypass via Empty OIDC Claims

The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in version 0.36.0 and prior to version 0.40.0, a privilege escalation vulnerability exists in the Flux Operator Web UI authentication code that allows aโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 10:25 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

6.9

CVSS4.0

CVE-2026-23986 - Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_syโ€ฆ

Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the `--UNSAFE,--trust` flag. As it โ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 10:20 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

6.8

CVSS4.0

CVE-2026-23968 - Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: falโ€ฆ

Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the `--UNSAFE,--trust` flag. As it โ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 10:13 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.

9.8

CVSS3.1

CVE-2026-23524 - Laravel Redis Horizontal Scaling Insecure Deserialization

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHPโ€™s unserialize() function without restricting which classes can be instantiated, which leaves users vulnerable to Remโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 10:07 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

7.3

CVSS4.0

CVE-2026-23960 - Argo Workflows affected by stored XSS in the artifact directory listing

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.6.17 and 3.7.8, stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another userโ€™s browser under the Argo Serveโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 10:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.

9.3

CVSS4.0

CVE-2026-23518 - Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were not veโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:50 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.

6.3

CVSS4.0

CVE-2026-23517 - Fleet has an Access Control vulnerability in debug/pprof endpoints

Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-privilege users could view internal server diagnostโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:45 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

8.5

CVSS4.0

CVE-2026-23526 - CVAT vulnerable to privilege escalation of users with staff status

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves superuser status and joining the admin group, which gives them full access to tโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:40 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

8.6

CVSS4.0

CVE-2026-23516 - CVAT vulnerable to XSS via skeleton SVG images

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided that they are able to create a maliciously crafted label in a CVAT task or projeโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:38 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.

8.5

CVSS4.0

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript. Depending on the deployment strategy, these filโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:36 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.
Total resulsts: 349182
Page 2036 of 34,919
ยซ previous page ยป next page
Filters