6.9

CVSS4.0

CVE-2026-5739 - PowerJob OpenAPI Endpoint addWorkflowNode GroovyEvaluator.evaluate code injection

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed …

📅 Published: April 7, 2026, 7:15 p.m. 🔄 Last Modified: April 8, 2026, 9:27 p.m.

6.3

CVSS4.0

CVE-2026-39365 - Vite has a Path Traversal in Optimized Deps `.map` Handling

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the serv…

📅 Published: April 7, 2026, 7:13 p.m. 🔄 Last Modified: April 15, 2026, 7:58 p.m.

8.2

CVSS4.0

CVE-2026-39364 - Vite has a `server.fs.deny` bypass with queries

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are a…

📅 Published: April 7, 2026, 7:12 p.m. 🔄 Last Modified: April 15, 2026, 8:01 p.m.

8.2

CVSS4.0

CVE-2026-39363 - Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw…

📅 Published: April 7, 2026, 7:10 p.m. 🔄 Last Modified: April 15, 2026, 8:07 p.m.

9.2

CVSS4.0

CVE-2026-39322 - PolarLearn: Any password authenticates banned accounts and grants API access

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. That session is then accepted across authenticated /api routes, enabling account data access and authe…

📅 Published: April 7, 2026, 7:03 p.m. 🔄 Last Modified: April 14, 2026, 6:44 p.m.

7.7

CVSS3.1

CVE-2026-39361 - OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_url

OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichment_table/mod.rs fails to block IPv6 addresses because Rust's url crate returns them with surrounding brackets (e.g. "[::1]" not "::1"). An authentica…

📅 Published: April 7, 2026, 7:02 p.m. 🔄 Last Modified: April 14, 2026, 8:28 p.m.

5.3

CVSS4.0

CVE-2026-39360 - RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltra…

RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization check in the multipart copy path (UploadPartCopy). A low-privileged user who cannot read objects from a victim bucket can still exfiltrate victim objects by copying them into an a…

📅 Published: April 7, 2026, 6:58 p.m. 🔄 Last Modified: April 10, 2026, 7:03 p.m.

10

CVSS3.1

CVE-2026-39355 - Genealogy is Missing Authorization in `TeamController::transferOwnership()` Allows Any Authenticate…

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces a…

📅 Published: April 7, 2026, 6:56 p.m. 🔄 Last Modified: April 10, 2026, 7:03 p.m.

6.5

CVSS3.1

CVE-2026-39354 - Scoold has an Authenticated Arbitrary Question Overwrite via Client-Controlled postId in POST /ques…

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /questions/ask. Be…

📅 Published: April 7, 2026, 6:54 p.m. 🔄 Last Modified: April 10, 2026, 7:29 p.m.

6.9

CVSS4.0

CVE-2026-39351 - Frappe allows unrestricted Doctype access via API exploit

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

📅 Published: April 7, 2026, 6:52 p.m. 🔄 Last Modified: April 10, 2026, 7:30 p.m.
Total resulsts: 344963
Page 206 of 34,497
« previous page » next page
Filters