8.7

CVSS4.0

CVE-2026-6819 - HKUDS OpenHarness Plugin Management Command Exposure

HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enable, /plugin disable, and /reload-plugins to remote senders by default. Attackers who gain access through the channel layer can remotely manage plugin trust and activation state, e…

πŸ“… Published: April 21, 2026, 7:41 p.m. πŸ”„ Last Modified: April 22, 2026, 2:23 p.m.

7.7

CVSS4.0

CVE-2026-40885 - goshs: Public collaborator feed leaks .goshs ACL credentials and enables unauthorized access

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the …

πŸ“… Published: April 21, 2026, 7:40 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

9.8

CVSS3.1

CVE-2026-40884 - goshs: Empty-username SFTP password authentication bypass in goshs

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install any SFTP p…

πŸ“… Published: April 21, 2026, 7:39 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.1

CVSS4.0

CVE-2026-40883 - goshs: CSRF in state-changing GET routes enables authenticated file deletion and directory creation

goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because go…

πŸ“… Published: April 21, 2026, 7:35 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

8.7

CVSS4.0

CVE-2026-40876 - SFTP root escape via prefix-based path validation in goshs

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expos…

πŸ“… Published: April 21, 2026, 7:34 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.5

CVSS3.1

CVE-2026-41320 - Frappe HR has possibility of SQL Injection due to improper field sanitization

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. Versions 15.54.0 and 1…

πŸ“… Published: April 21, 2026, 7:34 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.5

CVSS3.1

CVE-2026-40889 - Frappe HR has Improper Access Control on Files

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Versions 15.58.2 and 16.4.2 contain a patch. No known workarounds are available.

πŸ“… Published: April 21, 2026, 7:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.5

CVSS3.0

CVE-2026-40888 - Frappe HR vulnerable to Improper Access Control

Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting certain api endpoint. Versions 15.58.1 and 16.4.1 contain a patch. No known workarounds are availab…

πŸ“… Published: April 21, 2026, 7:28 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

9.1

CVSS3.1

CVE-2026-40887 - @vendure/core has a SQL Injection vulnerability

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression w…

πŸ“… Published: April 21, 2026, 7:24 p.m. πŸ”„ Last Modified: April 22, 2026, 9:08 p.m.

2.1

CVSS4.0

CVE-2026-40878 - mailcow-dockerized Login Page has Reflected Parameter Injection / Wrong-Context XSS Escaping

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface passes the raw `$_SERVER['REQUEST_URI']` to Twig as a global template variable and renders it inside a JavaScript string literal in the `setLang()` helper of `base.t…

πŸ“… Published: April 21, 2026, 7:21 p.m. πŸ”„ Last Modified: April 22, 2026, 9:02 p.m.
Total resulsts: 346087
Page 54 of 34,609
Β« previous page Β» next page
Filters