8.9

CVSS4.0

CVE-2026-41247 - elFinder: Command injection in resize background color parameter when using ImageMagick CLI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In cโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:47 p.m. ๐Ÿ”„ Last Modified: April 25, 2026, 1:25 a.m.

8.1

CVSS3.1

CVE-2026-41246 - Contour: Lua code injection via Cookie Path Rewrite Policy

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.rโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:44 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:20 p.m.

5.9

CVSS3.1

CVE-2026-41213 - @node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-forcโ€ฆ

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the aโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:33 p.m. ๐Ÿ”„ Last Modified: April 25, 2026, 1:23 a.m.

8.7

CVSS3.1

CVE-2026-41241 - pretalx: Stored cross-site scripting in organiser search typeahead

pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown using innerHTML string interpolation. Any user who controls one of those fields (which includes anyโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:30 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:23 p.m.

5.9

CVSS3.1

CVE-2026-41173 - Unbounded HTTP response body read in OpenTelemetry.Sampler.AWS

The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.Sampler.AWS reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory. AWSXRaySamplerClient.DoRequestAsyncโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:22 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:17 p.m.

9.3

CVSS4.0

CVE-2026-6074 - Path traversal: '.../...//' in Intrado 911 Emergency Gateway (EGW)

A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing network access the ability to access the EGW management interface without authentication. Successful exploitation of this vulnerability could allow a user to read, modify, or delete files.

๐Ÿ“… Published: April 23, 2026, 6:14 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:17 p.m.

7.7

CVSS3.1

CVE-2026-40886 - Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows controller

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:12 p.m. ๐Ÿ”„ Last Modified: April 25, 2026, 1:22 a.m.

7.4

CVSS4.0

CVE-2026-33694 - Junction File Manipulation

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEMโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:09 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 3:55 a.m.

5.9

CVSS3.1

CVE-2026-41078 - OpenTelemetry dotnet: Potential memory exhaustion via unbounded pooled-list sizing in Jaeger exportโ€ฆ

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under higโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:05 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:17 p.m.

5.3

CVSS3.1

CVE-2026-40894 - OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers

OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGeโ€ฆ

๐Ÿ“… Published: April 23, 2026, 6:03 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:22 p.m.
Total resulsts: 346583
Page 43 of 34,659
ยซ previous page ยป next page
Filters