9.1

CVSS3.1

CVE-2026-40322 - SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to surviโ€ฆ

๐Ÿ“… Published: April 16, 2026, 11 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 11 p.m.

8.5

CVSS3.1

CVE-2026-40318 - SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequeโ€ฆ

๐Ÿ“… Published: April 16, 2026, 10:54 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:48 a.m.

8.1

CVSS3.1

CVE-2026-40259 - SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts publish-service RoleReader tokens. The handler passes a caller-controlled id directly to a model functiโ€ฆ

๐Ÿ“… Published: April 16, 2026, 10:49 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:50 p.m.

4.3

CVSS3.1

CVE-2024-58343 -

Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.

๐Ÿ“… Published: April 16, 2026, 10:27 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:36 p.m.

6.1

CVSS3.1

CVE-2026-40255 - @adonisjs/http-server has an Open Redirect vulnerability

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions prior to 7.4.0, the response.redirect().back() method reads the Referer header from the incoming HTTP โ€ฆ

๐Ÿ“… Published: April 16, 2026, 10:25 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:25 p.m.

6.8

CVSS3.1

CVE-2026-40253 - openCryptoki: Memory safety vulnerabilities in BER/DER decoders in asn1.c

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common library (asn1.c) accept a raw pointer but no buffer length parameter, and trust attacker-controlled BER length fields without validating them aโ€ฆ

๐Ÿ“… Published: April 16, 2026, 10:04 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 11:16 p.m.

8.1

CVSS3.1

CVE-2026-41113 - TLS_QUIT Command Injection in sagredo qmail

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.

๐Ÿ“… Published: April 16, 2026, 10:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:09 p.m.

6.9

CVSS4.0

CVE-2026-40249 - free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subsโ€ฆ

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy Data notification subscriptions at /nudr-dr/v2/policy-data/subs-to-notify/{subsId} does not return after request body retrieval or deserialization errโ€ฆ

๐Ÿ“… Published: April 16, 2026, 9:59 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:47 a.m.

8.7

CVSS4.0

CVE-2026-40248 - free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Inโ€ฆ

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for creating or updating Traffic Influence Subscriptions checks whether the influenceId path segment equals subs-to-notify, but does not return after sending the HTTP 404 resโ€ฆ

๐Ÿ“… Published: April 16, 2026, 9:57 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 11:30 p.m.

8.7

CVSS4.0

CVE-2026-40247 - free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptioโ€ฆ

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for reading Traffic Influence Subscriptions checks whether the influenceId path segment equals subs-to-notify, but does not return after sending the HTTP 404 response when vaโ€ฆ

๐Ÿ“… Published: April 16, 2026, 9:54 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 11:30 p.m.
Total resulsts: 345151
Page 23 of 34,516
ยซ previous page ยป next page
Filters