2.1

CVSS4.0

CVE-2026-34248 - Zammad has an information disclosure in ticket detail view of customers in shared organizations

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, customers in shared organizations (means they can see each other's tickets) could see fields which are not intended for customers - including fields not intended for them at all (e.g. priority, custom ticket attribu…

📅 Published: April 8, 2026, 6 p.m. 🔄 Last Modified: April 9, 2026, 4:17 p.m.

7.5

CVSS3.1

CVE-2026-34392 - LORIS has a path traversal in static router

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory…

📅 Published: April 8, 2026, 5:57 p.m. 🔄 Last Modified: April 9, 2026, 2:23 p.m.

8.5

CVSS4.0

CVE-2026-30818 - OS Command Injection Vulnerability in dnsmasq Module in TP-Link AX53

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker t…

📅 Published: April 8, 2026, 5:54 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.8

CVSS4.0

CVE-2026-30817 - Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, pot…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.8

CVSS4.0

CVE-2026-30816 - Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, p…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

8.5

CVSS4.0

CVE-2026-30815 - OS Command Injection Vulnerability in OpenVPN Module in TP-Link AX53

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification …

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

3.7

CVSS3.1

CVE-2026-34166 - LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.length + replacement.length bytes to the memory limiter,…

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

7.3

CVSS4.0

CVE-2026-30814 - Buffer Overflow Vulnerability in TP-Link AX53

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow ar…

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

7.5

CVSS3.1

CVE-2026-33350 - LORIS has a SQL injection in MRI feedback popup

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging brows…

📅 Published: April 8, 2026, 5:47 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

7.8

CVSS3.1

CVE-2026-27806 - Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the p…

📅 Published: April 8, 2026, 5:40 p.m. 🔄 Last Modified: April 9, 2026, 2:24 p.m.
Total resulsts: 343738
Page 49 of 34,374
« previous page » next page
Filters