3.3

CVSS3.1

CVE-2026-21727 - Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record

--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana severity: Low cve: CVE-2026-21727 cvss_score: "3.3" cvss_vector: …

πŸ“… Published: April 15, 2026, 6:57 p.m. πŸ”„ Last Modified: April 24, 2026, 8 a.m.

9.2

CVSS4.0

CVE-2026-5189 - Nexus Repository 3 - Hardcoded Credential in Internal Database Component

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation …

πŸ“… Published: April 15, 2026, 6:43 p.m. πŸ”„ Last Modified: April 17, 2026, 3:08 p.m.

7.4

CVSS3.1

CVE-2026-33667 - OpenProject: 2FA OTP Verification Missing Rate Limiting

OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no rate limiting, lockout mechanism, or failed-attempt tracking. The existing brute_force_block_after_failed_logins s…

πŸ“… Published: April 15, 2026, 6:43 p.m. πŸ”„ Last Modified: April 28, 2026, 3:59 p.m.

5.5

CVSS3.1

CVE-2026-40915 - Gimp: gimp: heap buffer overflow due to integer overflow in fits image loader

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted FITS file. This integer overflow leads to a zero-byte memory allocation, which is then subjected to a heap buffer overflow when processing pixel data…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 5:28 p.m.

5

CVSS3.1

CVE-2026-40916 - Gimp: gimp: denial of service due to stack buffer overflow in tim image loader

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of Service (DoS). By opening a specially crafted TIM image file, the application crashes due to an unconditional overflow when writing to a variable-len…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:29 p.m.

5

CVSS3.1

CVE-2026-40917 - Gimp: gimp: application crashes or information disclosure via crafted icns image files

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An attacker could provide a malicious ICNS file, potentially leading to application crashes or information disclosure on systems that proc…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:21 p.m.

5.5

CVSS3.1

CVE-2026-40918 - Gimp: gimp: denial of service via crafted pvr image file

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due to a stack-based buffer overflow and an out-of-bounds read in the PVR image loader, causing the application to crash. Systems that process untrusted P…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:23 p.m.

6.1

CVSS3.1

CVE-2026-40919 - Gimp: gimp: denial of service via specially crafted seattle filmworks file

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted Seattle Filmworks file. A remote attacker could leverage this to cause a denial of service (DoS), leading to the plugin crashing and potenti…

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:20 p.m.

7.3

CVSS3.1

CVE-2026-6384 - Gimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processi…

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to write beyond an allocated buffer by processing a specially crafted GIF file. This can lead to a denial of service or potentially arbitrary code execution.

πŸ“… Published: April 15, 2026, 6:41 p.m. πŸ”„ Last Modified: April 28, 2026, 6:19 p.m.

5

CVSS3.1

CVE-2026-40256 - Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when …

πŸ“… Published: April 15, 2026, 6:36 p.m. πŸ”„ Last Modified: April 21, 2026, 2:02 p.m.
Total resulsts: 347742
Page 294 of 34,775
Β« previous page Β» next page
Filters