7.1

CVSS3.1

CVE-2026-41576 - Ajax30/BraveCMS-2.0: Stored HTML Injection in Contact Email via nl2br() and Unescaped Blade Template

Brave CMS is an open-source CMS. Prior to commit 6c56603, the contact form is publicly accessible (no authentication required). User-supplied message text is passed through PHP's nl2br() function, which converts newlines to <br> tags but does not escape HTML. The resulting string is then passed to …

πŸ“… Published: May 8, 2026, 2:50 p.m. πŸ”„ Last Modified: May 8, 2026, 2:50 p.m.

8.7

CVSS3.1

CVE-2026-41524 - Ajax30/BraveCMS-2.0: Stored XSS in Page / Article Content

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-ro…

πŸ“… Published: May 8, 2026, 2:50 p.m. πŸ”„ Last Modified: May 8, 2026, 2:50 p.m.

6.1

CVSS3.1

CVE-2026-41575 - th30d4y/IP: DOM-Based Cross-Site Scripting (XSS) Vulnerability

In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was directly rendered in the browser, allowing attackers to execute arbitrary JavaScript. This issue has been…

πŸ“… Published: May 8, 2026, 2:42 p.m. πŸ”„ Last Modified: May 8, 2026, 2:42 p.m.

9.3

CVSS4.0

CVE-2026-41574 - Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass

Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. This is only safe when the email has been verified by the OAuth provider. Nhost's controller trusts a…

πŸ“… Published: May 8, 2026, 2:40 p.m. πŸ”„ Last Modified: May 8, 2026, 2:40 p.m.

7.8

CVSS3.1

CVE-2026-41570 - PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes

PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string del…

πŸ“… Published: May 8, 2026, 2:33 p.m. πŸ”„ Last Modified: May 8, 2026, 2:33 p.m.

6.5

CVSS3.1

CVE-2026-41308 - Password Pusher: JSON API `/p.json` file upload alias bypasses file-push authentication

Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This …

πŸ“… Published: May 8, 2026, 2:30 p.m. πŸ”„ Last Modified: May 8, 2026, 2:30 p.m.

5.3

CVSS4.0

CVE-2026-41487 - Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of…

Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connection update flow. An authenticated, low-privileged user of role β€œmember” in a project could request the update of an exist…

πŸ“… Published: May 8, 2026, 2:27 p.m. πŸ”„ Last Modified: May 8, 2026, 2:27 p.m.

0.0

CVE-2026-43475 - scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT This resolves the follow splat and lock-up when running with PREEMPT_RT enabled on Hyper-V: [ 415.140818] BUG: scheduling while atomic: stress-ng-iomix/1048/0x00000002 [ …

πŸ“… Published: May 8, 2026, 2:22 p.m. πŸ”„ Last Modified: May 8, 2026, 2:22 p.m.

0.0

CVE-2026-43474 - fs: init flags_valid before calling vfs_fileattr_get

In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_get syzbot reported a uninit-value bug in [1]. Similar to the "*get" context where the kernel's internal file_kattr structure is initialized before calling vfs_fileattr_get(), we …

πŸ“… Published: May 8, 2026, 2:22 p.m. πŸ”„ Last Modified: May 8, 2026, 2:22 p.m.

0.0

CVE-2026-43473 - scsi: mpi3mr: Add NULL checks when resetting request and reply queues

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Add NULL checks when resetting request and reply queues The driver encountered a crash during resource cleanup when the reply and request queues were NULL due to freed memory. This issue occurred when the creation …

πŸ“… Published: May 8, 2026, 2:22 p.m. πŸ”„ Last Modified: May 8, 2026, 2:22 p.m.
Total resulsts: 349182
Page 3 of 34,919
Β« previous page Β» next page
Filters