7.5

CVSS3.1

CVE-2026-34392 - LORIS has a path traversal in static router

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory…

📅 Published: April 8, 2026, 5:57 p.m. 🔄 Last Modified: April 9, 2026, 2:23 p.m.

8.5

CVSS4.0

CVE-2026-30818 - OS Command Injection Vulnerability in dnsmasq Module in TP-Link AX53

An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrary code when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow the attacker t…

📅 Published: April 8, 2026, 5:54 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.8

CVSS4.0

CVE-2026-30817 - Arbitrary File Reading Vulnerability in dnsmasq Module in TP-Link AX53

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may allow unauthorized access to arbitrary files on the device, pot…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

6.8

CVSS4.0

CVE-2026-30816 - Arbitrary File Reading Vulnerability in OpenVPN Module in TP-Link AX53

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, p…

📅 Published: April 8, 2026, 5:53 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

8.5

CVSS4.0

CVE-2026-30815 - OS Command Injection Vulnerability in OpenVPN Module in TP-Link AX53

An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system commands when a specially crafted configuration file is processed due to insufficient input validation. Successful exploitation may allow modification …

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

3.7

CVSS3.1

CVE-2026-34166 - LiquidJS has a Memory Limit Bypass via Quadratic Amplification in `replace` Filter

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly accounts for memory usage when the memoryLimit option is enabled. It charges str.length + pattern.length + replacement.length bytes to the memory limiter,…

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

7.3

CVSS4.0

CVE-2026-30814 - Buffer Overflow Vulnerability in TP-Link AX53

A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow ar…

📅 Published: April 8, 2026, 5:52 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

7.5

CVSS3.1

CVE-2026-33350 - LORIS has a SQL injection in MRI feedback popup

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging brows…

📅 Published: April 8, 2026, 5:47 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

7.8

CVSS3.1

CVE-2026-27806 - Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the p…

📅 Published: April 8, 2026, 5:40 p.m. 🔄 Last Modified: April 9, 2026, 2:24 p.m.

5.3

CVSS4.0

CVE-2026-39851 - Saleor has a user enumeration vulnerability due to different error messages

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

📅 Published: April 8, 2026, 5:33 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.
Total resulsts: 343746
Page 50 of 34,375
« previous page » next page
Filters