9.3

CVSS4.0

CVE-2026-23751 - Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unaut…

📅 Published: April 23, 2026, 2:46 p.m. 🔄 Last Modified: April 25, 2026, 1:20 a.m.

6.9

CVSS3.1

CVE-2026-41238 - DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 through 3.3.3 are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prot…

📅 Published: April 23, 2026, 2:43 p.m. 🔄 Last Modified: April 23, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-62373 - Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integra…

📅 Published: April 23, 2026, 2:40 p.m. 🔄 Last Modified: April 23, 2026, 7:17 p.m.

7.8

CVSS3.1

CVE-2026-34003 - Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory…

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, lea…

📅 Published: April 23, 2026, 2:18 p.m. 🔄 Last Modified: April 23, 2026, 5:20 p.m.

7.8

CVSS3.1

CVE-2026-34001 - Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential me…

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially…

📅 Published: April 23, 2026, 2:14 p.m. 🔄 Last Modified: April 23, 2026, 4:22 p.m.

7.8

CVSS3.1

CVE-2026-33999 - Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map ha…

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service…

📅 Published: April 23, 2026, 2:11 p.m. 🔄 Last Modified: April 23, 2026, 4:16 p.m.

8.7

CVSS4.0

CVE-2026-35225 - Improper timeout handling in CODESYS EtherNetIP

An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

📅 Published: April 23, 2026, 1:54 p.m. 🔄 Last Modified: April 23, 2026, 3:37 p.m.

6.3

CVSS4.0

CVE-2026-41461 - SocialEngine <= 7.8.0 Blind SSRF via /core/link/preview

SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers ca…

📅 Published: April 23, 2026, 1:45 p.m. 🔄 Last Modified: April 23, 2026, 6:16 p.m.

9.3

CVSS4.0

CVE-2026-41460 - SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerab…

📅 Published: April 23, 2026, 1:44 p.m. 🔄 Last Modified: April 23, 2026, 4:16 p.m.

4.7

CVSS3.1

CVE-2025-66286 - Webkitgtk: authorization bypass through webpage::send-request signal handler

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests …

📅 Published: April 23, 2026, 12:15 p.m. 🔄 Last Modified: April 23, 2026, 1:16 p.m.
Total resulsts: 346640
Page 51 of 34,664
« previous page » next page
Filters