7.1

CVSS3.1

CVE-2026-35444 - SDL_image has a heap buffer overflow READ via unchecked colormap index in XCF loader

SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormapโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:44 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

9.8

CVSS3.0

CVE-2026-35471 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.

๐Ÿ“… Published: April 6, 2026, 9:38 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

8.1

CVSS3.1

CVE-2026-35442 - Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated uโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:36 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:30 p.m.

6.5

CVSS3.1

CVE-2026-35441 - Directus Affected by GraphQL Alias Amplification Denial-of-Service Due to Missing Query Cost/Compleโ€ฆ

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single request. An authenticated user could exploit GraphQL aliasing to repeat an expensiveโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:36 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:47 p.m.

5.3

CVSS3.1

CVE-2026-35413 - Directus GraphQL Schema SDL Disclosure Setting

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries (__schema, __type). However, the server_specs_graphql resolver on the /graphql/system eโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:34 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.1

CVSS3.1

CVE-2026-35412 - Directus has a TUS Upload Authorization Bypass Allows Arbitrary File Overwrite

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only coโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:33 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

4.3

CVSS3.1

CVE-2026-35411 - Directus is an Open Redirect in Admin 2FA Setup Page

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:33 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:37 p.m.

6.1

CVSS3.1

CVE-2026-35410 - Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed URLs as external, allowing attackers to bypass rโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:32 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:47 p.m.

7.7

CVSS4.0

CVE-2026-5709 - AWS Research and Engineering Studio (RES) FileBrowser Command Injection

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediaโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:32 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:53 a.m.

7.7

CVSS3.1

CVE-2026-35409 - Directus has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.0, a Server-Side Request Forgery (SSRF) protection bypass has been identified and fixed in Directus. The IP address validation mechanism used to block requests to local and private networks could be circโ€ฆ

๐Ÿ“… Published: April 6, 2026, 9:31 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343060
Page 45 of 34,306
ยซ previous page ยป next page
Filters