5.5

CVSS3.1

CVE-2026-39390 - CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using strip_tags() with an <iframe> allowlist and regex-bas…

📅 Published: April 8, 2026, 2:29 p.m. 🔄 Last Modified: April 8, 2026, 7:26 p.m.

6.7

CVSS3.1

CVE-2026-39389 - CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Prot…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0.

📅 Published: April 8, 2026, 2:28 p.m. 🔄 Last Modified: April 8, 2026, 7:26 p.m.

5.9

CVSS3.1

CVE-2026-39865 - Axios HTTP/2 Session Cleanup State Corruption Vulnerability

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSess…

📅 Published: April 8, 2026, 2:25 p.m. 🔄 Last Modified: April 8, 2026, 7:26 p.m.

6.4

CVSS3.1

CVE-2025-58713 - Rhpam: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-57853 - Web-terminal: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root us…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-57854 - Osus-operator: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, ev…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2025-57851 - Mce: privilege escalation via excessive /etc/passwd permissions

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container,…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:26 p.m.

6.4

CVSS3.1

CVE-2025-57847 - Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissi…

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container…

📅 Published: April 8, 2026, 1:55 p.m. 🔄 Last Modified: April 8, 2026, 7:39 p.m.

7.4

CVSS3.1

CVE-2026-5795 - ThreadLocal Variable Leak Allows Thread-Based Privilege Escalation in Eclipse Jetty JASPIAuthentica…

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent requ…

📅 Published: April 8, 2026, 1:32 p.m. 🔄 Last Modified: April 8, 2026, 7:39 p.m.

6.4

CVSS3.1

CVE-2026-2509 - Page Builder: Pagelayer <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via But…

The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Custom Attributes field in all versions up to, and including, 2.0.8. This is due to an incomplete event handler blocklist in the 'pagelayer_xss_content' XSS filtering function, whic…

📅 Published: April 8, 2026, 1:26 p.m. 🔄 Last Modified: April 8, 2026, 7:27 p.m.
Total resulsts: 343480
Page 28 of 34,348
« previous page » next page
Filters