6.9

CVSS4.0

CVE-2026-5971 - FoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injection

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated codโ€ฆ

๐Ÿ“… Published: April 9, 2026, 6 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 9:31 a.m.

8.7

CVSS4.0

CVE-2026-39911 - Hashgraph Guardian 3.5.0 Unsandboxed JavaScript Execution RCE

Hashgraph Guardian through version 3.5.0 contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to execute arbitrary code by passing user-supplied JavaScript expressions directly to the Node.js Function() โ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:57 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:20 p.m.

6.1

CVSS3.1

CVE-2026-39315 - Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()

Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documentation explicitly recommends for rendering user-supplied content in <head> safely. Internally, the hasDangerousProtocol() function in packages/unhead/src/plugins/safe.ts decodes Hโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:54 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:17 p.m.

8.5

CVSS3.1

CVE-2026-5329 - Rapid7 Velociraptor Improper Input Validation in Client Message Handler

Rapid7 Velociraptor versions prior to 0.76.2ย contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring mโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:52 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:58 p.m.

5.4

CVSS3.1

CVE-2026-35207 - deepinid plugin in dde-control-center is configured to skip TLS certificate verification when downlโ€ฆ

dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from openโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:48 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:52 a.m.

1.7

CVSS4.0

CVE-2026-40072 - web3.py affected by SSRF via CCIP Read (EIP-3668) OffchainLookup URL handling

web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web3.py implements CCIP Read / OffchainLookup (EIP-3668) by performing HTTP requests to URLs supplied by smart contracts in offchain_lookup_payload["urls"]. The implementation uses tโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:41 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 7:37 p.m.

5.4

CVSS3.1

CVE-2026-40071 - pyLoad WebUI JSON permission mismatch lets ADD/DELETE users invoke MODIFY-only actions

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execuโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:36 p.m. ๐Ÿ”„ Last Modified: April 10, 2026, 8:52 a.m.

8.1

CVSS3.1

CVE-2026-40070 - bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and iโ€ฆ

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier's signature over the certificate contents. In acquisition_protocol: 'direct', the caller supplies alโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:26 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:17 p.m.

7.5

CVSS3.1

CVE-2026-40069 - bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus aโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:22 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:17 p.m.

9.3

CVSS4.0

CVE-2026-39987 - marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocketโ€ฆ

๐Ÿ“… Published: April 9, 2026, 5:16 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 6:17 p.m.
Total resulsts: 343935
Page 42 of 34,394
ยซ previous page ยป next page
Filters