2.9

CVSS3.1

CVE-2026-40947 - Unintended DLL Search Path in Yubico Authentication Libraries

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.

πŸ“… Published: April 15, 2026, 11:13 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.7

CVSS4.0

CVE-2026-40192 - Pillow is vulnerable to a FITS GZIP decompression bomb

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of ser…

πŸ“… Published: April 15, 2026, 10:53 p.m. πŸ”„ Last Modified: April 22, 2026, 8:08 p.m.

8.8

CVSS3.1

CVE-2026-40316 - OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run wit…

πŸ“… Published: April 15, 2026, 10:49 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

5.4

CVSS3.1

CVE-2026-39350 - Istio AuthorizationPolicy Incorrect Regex Matching of Dots in serviceAccounts Fields Allows Policy …

Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 through 1.28.5, 1.29.0, and 1.29.1, the serviceAccounts and notServiceAccounts fields in AuthorizationPolicy incorrectly interpret dots (.) as a regular expression matcher. Because . is…

πŸ“… Published: April 15, 2026, 10:42 p.m. πŸ”„ Last Modified: April 23, 2026, 8 p.m.

5.3

CVSS4.0

CVE-2026-40179 - Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escap…

πŸ“… Published: April 15, 2026, 10:26 p.m. πŸ”„ Last Modified: April 22, 2026, 8:04 p.m.

4.3

CVSS3.1

CVE-2026-4949 - ProfilePress <= 4.16.12 - Missing Authorization to Authenticated (Subscriber+) Inactive Membership …

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function not properly enforcing …

πŸ“… Published: April 15, 2026, 10:26 p.m. πŸ”„ Last Modified: April 16, 2026, 2:19 p.m.

4.8

CVSS4.0

CVE-2026-1711 - Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerabi…

Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interface component. Requires a high privileged user with a developer role.

πŸ“… Published: April 15, 2026, 9:32 p.m. πŸ”„ Last Modified: April 23, 2026, 8:01 p.m.

5.1

CVSS4.0

CVE-2026-1564 - Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a us…

Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface component. Requires a high privileged user with a developer role.

πŸ“… Published: April 15, 2026, 9:31 p.m. πŸ”„ Last Modified: April 23, 2026, 8:02 p.m.

6.1

CVSS4.0

CVE-2026-40500 - ProcessWire CMS SSRF via Add Module From URL

ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the module download parameter, causing the server to issue outbound HTTP requests to …

πŸ“… Published: April 15, 2026, 9:25 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.8

CVSS3.1

CVE-2026-40261 - Composer has Command Injection via Malicious Perforce Reference

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::ge…

πŸ“… Published: April 15, 2026, 8:56 p.m. πŸ”„ Last Modified: April 25, 2026, 6:12 p.m.
Total resulsts: 347741
Page 290 of 34,775
Β« previous page Β» next page
Filters