8.8

CVSS3.1

CVE-2026-40261 - Composer has Command Injection via Malicious Perforce Reference

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::syncCodeBase() method, which appends the $sourceReference parameter to a shell command without proper escaping, and additionally in the Perforce::ge…

📅 Published: April 15, 2026, 8:56 p.m. 🔄 Last Modified: April 25, 2026, 6:12 p.m.

7.8

CVSS3.1

CVE-2026-40176 - Composer is vulnerable to Command Injection via Malicious Perforce Repository

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) witho…

📅 Published: April 15, 2026, 8:47 p.m. 🔄 Last Modified: April 25, 2026, 6:24 p.m.

8.5

CVSS4.0

CVE-2026-22676 - Barracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory Permissions

Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gain SYSTEM-level privileges by exploiting overly permissive filesystem ACLs on the C:\Windows\Automation directory. Attackers can modify existing automation content or place attacke…

📅 Published: April 15, 2026, 8:45 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

9.4

CVSS3.1

CVE-2026-40173 - Dgraph: Unauthenticated pprof endpoint leaks admin auth token

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line inclu…

📅 Published: April 15, 2026, 8:40 p.m. 🔄 Last Modified: April 25, 2026, 6:27 p.m.

6.1

CVSS3.1

CVE-2026-40186 - ApostropheCMS: sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements

ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). Apostroph…

📅 Published: April 15, 2026, 8:15 p.m. 🔄 Last Modified: April 25, 2026, 6:15 p.m.

5.3

CVSS3.1

CVE-2026-39857 - Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field …

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the publicApiProjection…

📅 Published: April 15, 2026, 7:38 p.m. 🔄 Last Modified: April 20, 2026, 5:03 p.m.

8.7

CVSS3.1

CVE-2026-35569 - ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendered without proper output encoding into HTML contexts includin…

📅 Published: April 15, 2026, 7:34 p.m. 🔄 Last Modified: April 30, 2026, 8:08 p.m.

9.1

CVSS3.1

CVE-2026-6388 - Argocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient n…

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on…

📅 Published: April 15, 2026, 7:30 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

5.4

CVSS3.1

CVE-2026-33889 - ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escapin…

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color values prefixed with -- bypass TinyColor validation intended for CSS custom properties, and the laun…

📅 Published: April 15, 2026, 7:29 p.m. 🔄 Last Modified: April 20, 2026, 5:03 p.m.

5.3

CVSS3.1

CVE-2026-33888 - ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, where the method checks whether a MongoDB projection has already been set before applying th…

📅 Published: April 15, 2026, 7:25 p.m. 🔄 Last Modified: April 20, 2026, 5:04 p.m.
Total resulsts: 347742
Page 291 of 34,775
« previous page » next page
Filters