5.3

CVSS3.1

CVE-2026-39857 - Information Disclosure via `choices`/`counts` Query Parameters Bypassing publicApiProjection Field …

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the publicApiProjection…

📅 Published: April 15, 2026, 7:38 p.m. 🔄 Last Modified: April 17, 2026, 3:08 p.m.

8.7

CVSS3.1

CVE-2026-35569 - ApostropheCMS: Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta Description), where user-controlled input is rendered without proper output encoding into HTML contexts includin…

📅 Published: April 15, 2026, 7:34 p.m. 🔄 Last Modified: April 17, 2026, 3:08 p.m.

9.1

CVSS3.1

CVE-2026-6388 - Argocd-image-updater: argocd image updater: cross-namespace privilege escalation via insufficient n…

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on…

📅 Published: April 15, 2026, 7:30 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

5.4

CVSS3.1

CVE-2026-33889 - ApostropheCMS: Stored XSS via CSS Custom Property Injection in `@apostrophecms/color-field` Escapin…

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color values prefixed with -- bypass TinyColor validation intended for CSS custom properties, and the laun…

📅 Published: April 15, 2026, 7:29 p.m. 🔄 Last Modified: April 17, 2026, 3:08 p.m.

5.3

CVSS3.1

CVE-2026-33888 - ApostropheCMS: publicApiProjection Bypass via `project` Query Builder in Piece-Type REST API

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, where the method checks whether a MongoDB projection has already been set before applying th…

📅 Published: April 15, 2026, 7:25 p.m. 🔄 Last Modified: April 17, 2026, 3:08 p.m.

5.3

CVSS3.1

CVE-2026-21726 - Loki Path Traversal - CVE-2021-36156 Bypass

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

📅 Published: April 15, 2026, 7:24 p.m. 🔄 Last Modified: April 18, 2026, 7:30 p.m.

9.1

CVSS3.1

CVE-2025-41118 - Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Py…

📅 Published: April 15, 2026, 7:15 p.m. 🔄 Last Modified: April 18, 2026, 5:30 p.m.

6.5

CVSS3.1

CVE-2026-6385 - Ffmpeg: ffmpeg: denial of service and potential arbitrary code execution via signed integer overflo…

A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks…

📅 Published: April 15, 2026, 7:11 p.m. 🔄 Last Modified: April 17, 2026, 3:17 p.m.

3.7

CVSS3.1

CVE-2026-33877 - ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows unauthenticated username and email enumeration. When a user is not found, …

📅 Published: April 15, 2026, 7:11 p.m. 🔄 Last Modified: April 17, 2026, 3:08 p.m.

6.5

CVSS3.1

CVE-2026-6364 - Skia: Google Chrome: Chromium: Skia: Information disclosure via out-of-bounds read in Google Chrome

Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium)

📅 Published: April 15, 2026, 7:04 p.m. 🔄 Last Modified: April 17, 2026, 7:19 p.m.
Total resulsts: 345139
Page 36 of 34,514
« previous page » next page
Filters