6.3

CVSS3.1

CVE-2026-27299 - Adobe Framemaker | Improper Input Validation (CWE-20)

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the system. Exploitation of this issue requires user interaction …

πŸ“… Published: April 14, 2026, 10:58 p.m. πŸ”„ Last Modified: April 15, 2026, 5:36 p.m.

7.8

CVSS3.1

CVE-2026-27293 - Adobe Framemaker | Heap-based Buffer Overflow (CWE-122)

Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: April 14, 2026, 10:58 p.m. πŸ”„ Last Modified: April 14, 2026, 11:16 p.m.

7.8

CVSS3.1

CVE-2026-27292 - Adobe Framemaker | Use After Free (CWE-416)

Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: April 14, 2026, 10:58 p.m. πŸ”„ Last Modified: April 14, 2026, 11:16 p.m.

7.2

CVSS3.1

CVE-2026-39387 - BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter

BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local File Inclusion (LFI) attack via the tpl parameter, which can lead to Remote Code Execution (RCE).The application fails to…

πŸ“… Published: April 14, 2026, 10:56 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8

CVSS3.1

CVE-2026-35589 - nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update)

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's WebSocket server in bridge/src/server.ts, resulting from an incomplete remediation of CVE-2026-2577. The original fix changed the binding from 0.0.0.0 to…

πŸ“… Published: April 14, 2026, 10:47 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

4

CVSS4.0

CVE-2026-33414 - PowerShell Command Injection in Podman HyperV Machine

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $()…

πŸ“… Published: April 14, 2026, 10:42 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

6.7

CVSS3.1

CVE-2026-40688 - Out‑of‑Bounds Write Allowing Remote Code Execution in Fortinet FortiWeb

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.

πŸ“… Published: April 14, 2026, 10:35 p.m. πŸ”„ Last Modified: April 17, 2026, 3:12 p.m.

6.5

CVSS3.1

CVE-2026-35034 - Jellyfin: Potential Application DoS from excessively large SyncPlay group names

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creation endpoint (POST /SyncPlay/New), where an authenticated user can create groups with names of unlimited size due to insufficient input validation. By …

πŸ“… Published: April 14, 2026, 10:31 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

9.3

CVSS4.0

CVE-2026-35033 - Jellyfin: Potential SSRF + Arbitrary file read via stream argument injection

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in StreamingHelpers.cs adds any lowerc…

πŸ“… Published: April 14, 2026, 10:28 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

8.6

CVSS4.0

CVE-2026-35032 - Jellyfin: Potential SSRF + Arbitrary file read via LiveTV M3U tuner

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP …

πŸ“… Published: April 14, 2026, 10:25 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 345142
Page 56 of 34,515
Β« previous page Β» next page
Filters