7

CVSS4.0

CVE-2026-5263 - URI nameConstraints not enforced in ConfirmNameConstraints()

URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification in wolfcrypt/src/asn.c. A compromised or malicious sub-CA could issue leaf certificates with URI SAN entries that violate the nameConstraints of the issuing CA, and wolfSSL would …

📅 Published: April 9, 2026, 9:15 p.m. 🔄 Last Modified: April 10, 2026, 6:09 p.m.

8.7

CVSS4.0

CVE-2026-5981 - D-Link DIR-605L POST Request formAdvFirewall buffer overflow

A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform/formAdvFirewall of the component POST Request Handler. Such manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has be…

📅 Published: April 9, 2026, 9:15 p.m. 🔄 Last Modified: April 9, 2026, 9:15 p.m.

9.3

CVSS4.0

CVE-2026-40111 - PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.p…

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py. No sanitization is performed and shell metachara…

📅 Published: April 9, 2026, 9:14 p.m. 🔄 Last Modified: April 10, 2026, 9:29 a.m.

3.1

CVSS3.1

CVE-2026-40109 - Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliati…

Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This allows any val…

📅 Published: April 9, 2026, 9:06 p.m. 🔄 Last Modified: April 10, 2026, 9:29 a.m.

8.7

CVSS4.0

CVE-2026-40107 - SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering

SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with src attributes survive Mermaid's internal DOMPurify and land in SVG <foreignObject> blocks. The SVG is injected via innerHTM…

📅 Published: April 9, 2026, 9:03 p.m. 🔄 Last Modified: April 10, 2026, 6:12 p.m.

6

CVSS4.0

CVE-2026-5446 - wolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuse

In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is stateless and passes the caller-supplied IV verbatim to the MagicCrypto SDK with no internal counter, and because the explicit IV is zero…

📅 Published: April 9, 2026, 9:02 p.m. 🔄 Last Modified: April 10, 2026, 6:11 p.m.

4.8

CVSS4.0

CVE-2026-35206 - Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment

Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart URL | repo/chartname] to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as give…

📅 Published: April 9, 2026, 9:02 p.m. 🔄 Last Modified: April 9, 2026, 9:02 p.m.

8.7

CVSS4.0

CVE-2026-5980 - D-Link DIR-605L POST Request formSetMACFilter buffer overflow

A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit h…

📅 Published: April 9, 2026, 9 p.m. 🔄 Last Modified: April 9, 2026, 9 p.m.

5.1

CVSS4.0

CVE-2023-54364 - Joomla HikaShop 4.7.4 Reflected XSS via Product Filter

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, fr…

📅 Published: April 9, 2026, 8:54 p.m. 🔄 Last Modified: April 10, 2026, 6:10 p.m.

5.1

CVSS4.0

CVE-2023-54363 - Joomla Solidres 2.13.3 Reflected XSS via Multiple Parameters

Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can cr…

📅 Published: April 9, 2026, 8:54 p.m. 🔄 Last Modified: April 10, 2026, 3:55 p.m.
Total resulsts: 343887
Page 31 of 34,389
« previous page » next page
Filters