7.2

CVSS3.1

CVE-2026-40871 - mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint stores quarantine_category without validation or sanitizatio…

📅 Published: April 21, 2026, 7:12 p.m. 🔄 Last Modified: April 22, 2026, 9:02 p.m.

7.5

CVSS3.1

CVE-2026-40869 - Decidim amendments can be accepted or rejected by anyone

Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is …

📅 Published: April 21, 2026, 7:08 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

7.5

CVSS3.1

CVE-2026-40870 - Decidim's comments API allows access to all commentable resources

Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission checks. All Decidim instances are impacted that hav…

📅 Published: April 21, 2026, 7:06 p.m. 🔄 Last Modified: April 22, 2026, 9:08 p.m.

4.8

CVSS3.1

CVE-2026-22751 - Spring Security JdbcOneTimeTokenService allows a one-time token to authenticate multiple sessions

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.…

📅 Published: April 21, 2026, 6:30 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

5.1

CVSS4.0

CVE-2026-6745 - Bagisto Custom Scripts cross site scripting

A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may b…

📅 Published: April 21, 2026, 6:30 p.m. 🔄 Last Modified: April 22, 2026, 7 a.m.

8.1

CVSS3.1

CVE-2026-40868 - kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a policy does not explicitly set an Authorization header. Becaus…

📅 Published: April 21, 2026, 6:22 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

7.1

CVSS4.0

CVE-2026-40867 - Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files an…

📅 Published: April 21, 2026, 6:16 p.m. 🔄 Last Modified: April 22, 2026, 9:05 p.m.

8.6

CVSS4.0

CVE-2026-40866 - Horilla: Unauthorized Document Overwrite via File Upload Endpoint

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employee’s document by changing the document ID in the upload re…

📅 Published: April 21, 2026, 6:15 p.m. 🔄 Last Modified: April 22, 2026, 9:05 p.m.

7.1

CVSS4.0

CVE-2026-40865 - Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>

Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR …

📅 Published: April 21, 2026, 6:14 p.m. 🔄 Last Modified: April 22, 2026, 9:05 p.m.

8.5

CVSS4.0

CVE-2026-40614 - PJSIP: Heap buffer overflow in Opus codec decoding

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer overflow when decoding Opus audio frames due to insufficient buffer size validation in the Opus codec decode path. The FEC decode buffers (dec_frame[].buf) were allocated based on a…

📅 Published: April 21, 2026, 6:04 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.
Total resulsts: 346087
Page 56 of 34,609
« previous page » next page
Filters