5.3

CVSS4.0

CVE-2026-41472 - CyberPanel < 2.4.4 Stored XSS via AI Scanner Dashboard

CyberPanel versions prior toΒ 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of Scan…

πŸ“… Published: April 24, 2026, 8:40 p.m. πŸ”„ Last Modified: April 28, 2026, 3:45 p.m.

7.8

CVSS3.1

CVE-2026-41477 - Deskflow: Local privilege escalation via unauthenticated IPC

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing any local unprivileged user to execute arbitrary …

πŸ“… Published: April 24, 2026, 7:50 p.m. πŸ”„ Last Modified: April 28, 2026, 3:46 p.m.

7.4

CVSS4.0

CVE-2026-41476 - Deskflow: clipboard deserialization global-buffer-overflow

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected peer to trigger an out-of-bounds read by sending a malformed clipboard update. The issue is in the implementation of src/lib/deskflow/I…

πŸ“… Published: April 24, 2026, 7:47 p.m. πŸ”„ Last Modified: April 28, 2026, 3:47 p.m.

7.1

CVSS4.0

CVE-2026-6968 - Multiple Path Traversal Variants in awslabs/tough

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked …

πŸ“… Published: April 24, 2026, 7:44 p.m. πŸ”„ Last Modified: April 24, 2026, 9:16 p.m.

8.7

CVSS4.0

CVE-2026-41503 - BACnet Stack: Out-of-Bounds Read in ReadPropertyMultiple Property Decoder via Deprecated Tag Parser

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service property decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending an RPM …

πŸ“… Published: April 24, 2026, 7:41 p.m. πŸ”„ Last Modified: April 28, 2026, 3:30 p.m.

7.1

CVSS4.0

CVE-2026-6967 - Missing Delegated Metadata Validation in awslabs/tough

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local metadata cache,…

πŸ“… Published: April 24, 2026, 7:41 p.m. πŸ”„ Last Modified: April 24, 2026, 9:16 p.m.

8.7

CVSS4.0

CVE-2026-41502 - BACnet Stack: Off-by-One Out-of-Bounds Read in ReadPropertyMultiple Object ID Decoder

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service decoder allows unauthenticated remote attackers to read one byte past an allocated buffer boundary by sen…

πŸ“… Published: April 24, 2026, 7:40 p.m. πŸ”„ Last Modified: April 28, 2026, 3:35 p.m.

8.7

CVSS4.0

CVE-2026-41475 - BACnet Stack: Out-of-Bounds Read in WritePropertyMultiple Decoder via Deprecated Tag Parser

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM…

πŸ“… Published: April 24, 2026, 7:39 p.m. πŸ”„ Last Modified: April 27, 2026, 8:15 p.m.

7

CVSS4.0

CVE-2026-6966 - Signature Threshold Bypass in awslabs/tough Delegated Roles

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegated role met…

πŸ“… Published: April 24, 2026, 7:38 p.m. πŸ”„ Last Modified: April 24, 2026, 9:16 p.m.

8.4

CVSS3.1

CVE-2026-41433 - OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file over…

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a local attacker controlling a Java workload to overwrite arbitrary host files when Java injection is enabled and OBI is r…

πŸ“… Published: April 24, 2026, 7:26 p.m. πŸ”„ Last Modified: April 28, 2026, 9:17 a.m.
Total resulsts: 346939
Page 44 of 34,694
Β« previous page Β» next page
Filters