7.7

CVSS3.1

CVE-2026-34242 - Weblate: Arbitrary File Read via Symlink

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.

πŸ“… Published: April 15, 2026, 6:19 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

5

CVSS3.1

CVE-2026-33440 - Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.

πŸ“… Published: April 15, 2026, 6:15 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.1

CVSS3.1

CVE-2026-33435 - Weblate: Remote code execution during backup restoration

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediatel…

πŸ“… Published: April 15, 2026, 6:13 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.4

CVSS3.1

CVE-2026-4857 - SailPoint IdentityIQ Debug UI Incorrect Authorization

IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new Identity…

πŸ“… Published: April 15, 2026, 6:08 p.m. πŸ”„ Last Modified: April 17, 2026, 3:08 p.m.

6.8

CVSS3.1

CVE-2026-33220 - Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature …

πŸ“… Published: April 15, 2026, 6:03 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

5.4

CVSS3.1

CVE-2026-6383 - Kubevirt: kubevirt: unauthorized subresource access due to improper rbac evaluation

A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names, leading to incorrect permission evaluations. This allows authenticated users with specific custom roles to gain unauthorized access to subresources, …

πŸ“… Published: April 15, 2026, 6:03 p.m. πŸ”„ Last Modified: April 17, 2026, 3:08 p.m.

4.3

CVSS3.1

CVE-2026-33214 - Weblate has improper access control for the translation memory API

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by …

πŸ“… Published: April 15, 2026, 5:51 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

3.1

CVSS3.1

CVE-2026-33212 - Weblate: Improper access control for pending tasks in API

Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of the task, so exploitin…

πŸ“… Published: April 15, 2026, 5:48 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8

CVSS3.1

CVE-2026-6290 - Velociraptor Query() Plugin Misapplies Permissions To Orgs

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which …

πŸ“… Published: April 15, 2026, 5:29 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

7.4

CVSS3.1

CVE-2026-32631 - Git for Windows: `git clone` from manipulated repositories can leak NTLM hashes to arbitrary servers

Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an …

πŸ“… Published: April 15, 2026, 5:26 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 345149
Page 41 of 34,515
Β« previous page Β» next page
Filters