9.3

CVSS4.0

CVE-2026-25660 - Authentication bypass for certain API calls

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls.  This bypass allows assigning arbitrary permission to any user existing in CodeChec…

📅 Published: April 24, 2026, 1:10 p.m. 🔄 Last Modified: April 27, 2026, 2:48 p.m.

9.9

CVSS3.1

CVE-2026-21515 - Azure IoT Central Elevation of Privilege Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

📅 Published: April 24, 2026, 12:51 p.m. 🔄 Last Modified: April 24, 2026, 2:39 p.m.

4.3

CVSS3.1

CVE-2026-38743 - Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities

The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access to at least one DAG could retrieve HITL prompts (including their request parameters) and full TaskInstance details for …

📅 Published: April 24, 2026, 12:36 p.m. 🔄 Last Modified: April 27, 2026, 12:24 p.m.

4.3

CVSS3.1

CVE-2026-40690 - Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies…

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are reco…

📅 Published: April 24, 2026, 12:35 p.m. 🔄 Last Modified: April 27, 2026, 12:24 p.m.

6.5

CVSS3.1

CVE-2026-5265 - Ovn: ovn: heap over-read in icmp error response generation - security issue

When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total length (ip_tot_len for IPv4, ip6_plen for IPv6) without validating it against the actual packet buffer s…

📅 Published: April 24, 2026, 12:25 p.m. 🔄 Last Modified: April 24, 2026, 6:21 p.m.

8.6

CVSS3.1

CVE-2026-5367 - Ovn: ovn: information disclosure via crafted dhcpv6 packets

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to th…

📅 Published: April 24, 2026, 12:25 p.m. 🔄 Last Modified: April 24, 2026, 6:17 p.m.

2.4

CVSS4.0

CVE-2026-4313 - Stored XSS in AdaptiveGRC

AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the value of the text field in the HTTP POST request. Improper parameter validation by the server results in arbitrary JavaScript execution in the victim's browser. Critically, this may…

📅 Published: April 24, 2026, 11:05 a.m. 🔄 Last Modified: April 24, 2026, 2:39 p.m.

8.8

CVSS4.0

CVE-2026-6043 - Insecure Default Configuration in P4 Server

P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate existing users, authenticate to accounts with no password set, and access depot contents via the bu…

📅 Published: April 24, 2026, 11:02 a.m. 🔄 Last Modified: April 25, 2026, 7:17 a.m.

8.1

CVSS3.1

CVE-2026-23902 - Apache DolphinScheduler: Users are able to use tenants that are not defined on the platform during …

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1.  Users are recommended to up…

📅 Published: April 24, 2026, 10:56 a.m. 🔄 Last Modified: April 27, 2026, 1:42 p.m.

6.3

CVSS3.1

CVE-2025-62233 - Apache DolphinScheduler: Deserialization of untrusted data in RPC

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious …

📅 Published: April 24, 2026, 10:54 a.m. 🔄 Last Modified: April 27, 2026, 1:45 p.m.
Total resulsts: 349182
Page 286 of 34,919
« previous page » next page
Filters