5

CVSS3.1

CVE-2026-40256 - Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when …

πŸ“… Published: April 15, 2026, 6:36 p.m. πŸ”„ Last Modified: April 21, 2026, 2:02 p.m.

8.2

CVSS3.1

CVE-2026-34632 - Photoshop Installer | CWE-427: Uncontrolled Search Path Element

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. A low-privileged local attacker could have exploited this vulnerability by manipulating the search path used by the ap…

πŸ“… Published: April 15, 2026, 6:35 p.m. πŸ”„ Last Modified: April 22, 2026, 4:23 p.m.

4.1

CVSS3.1

CVE-2026-39845 - Weblate: SSRF via the webhook add-on using unprotected fetch_url()

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.

πŸ“… Published: April 15, 2026, 6:26 p.m. πŸ”„ Last Modified: April 21, 2026, 2:05 p.m.

8.8

CVSS3.1

CVE-2026-34393 - Weblate: Privilege escalation in the user API endpoint

Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.

πŸ“… Published: April 15, 2026, 6:24 p.m. πŸ”„ Last Modified: April 21, 2026, 2:05 p.m.

5

CVSS3.1

CVE-2026-34244 - Weblate: SSRF via Project-Level Machinery Configuration

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate m…

πŸ“… Published: April 15, 2026, 6:22 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

5.5

CVSS3.1

CVE-2026-6245 - Sssd: out-of-bounds read in the sssd

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes received from a pipe. Because the data is treated as a NUL-terminated C string without explicit termination, it results in a…

πŸ“… Published: April 15, 2026, 6:20 p.m. πŸ”„ Last Modified: April 17, 2026, 3:08 p.m.

7.7

CVSS3.1

CVE-2026-34242 - Weblate: Arbitrary File Read via Symlink

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.

πŸ“… Published: April 15, 2026, 6:19 p.m. πŸ”„ Last Modified: April 21, 2026, 2:07 p.m.

5

CVSS3.1

CVE-2026-33440 - Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.

πŸ“… Published: April 15, 2026, 6:15 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.1

CVSS3.1

CVE-2026-33435 - Weblate: Remote code execution during backup restoration

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediatel…

πŸ“… Published: April 15, 2026, 6:13 p.m. πŸ”„ Last Modified: April 21, 2026, 2:10 p.m.

8.4

CVSS3.1

CVE-2026-4857 - SailPoint IdentityIQ Debug UI Incorrect Authorization

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new Identity…

πŸ“… Published: April 15, 2026, 6:08 p.m. πŸ”„ Last Modified: April 17, 2026, 3:08 p.m.
Total resulsts: 347773
Page 298 of 34,778
Β« previous page Β» next page
Filters