8.1

CVSS3.1

CVE-2026-40588 - blueprintUE: Authenticated Password Change Does Not Verify Current Password

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit/ does not include a current_password field and does not verify the user's existing password before accepting a new one. Any attacker who obtains a valid authenticated session β€” t…

πŸ“… Published: April 21, 2026, 5:12 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.

6.5

CVSS3.1

CVE-2026-40587 - blueprintUE: Active Sessions Are Not Invalidated After Password Change or Reset

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profile edit page, or when a password reset is completed via the reset link, neither operation invalidates existing authenticated sessions for that user. A server-side session store as…

πŸ“… Published: April 21, 2026, 5:11 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.

7.5

CVSS3.1

CVE-2026-40586 - blueprintUE: Login Endpoint Has No Rate Limiting, Lockout, or Brute-Force Protection

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of any kind. Failed authentication attempts are processed at full network speed with no IP-based rate limiting, no per-account attempt counter, no temporary lockout, no progressive …

πŸ“… Published: April 21, 2026, 5:10 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.

7.1

CVSS3.1

CVE-2026-41191 - FreeScout's signature only mailbox permission allows unauthorized mailbox chat setting changes

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside the allowed-field filter. A user with only the mailbox `sig` permission sees only the signature field in the UI, but can still change the hid…

πŸ“… Published: April 21, 2026, 5:09 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

7.4

CVSS3.1

CVE-2026-40585 - blueprintUE: Password Reset Tokens Have No Expiry Window

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-character CSPRNG token is generated and stored alongside a password_reset_at timestamp. However, the token redemption function findUserIDFromEmailAndToken() queries only for a matching …

πŸ“… Published: April 21, 2026, 5:09 p.m. πŸ”„ Last Modified: April 22, 2026, 9:16 p.m.

7.1

CVSS3.1

CVE-2026-41190 - FreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft …

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `save_draft` AJAX path is weaker. A direct POST can creat…

πŸ“… Published: April 21, 2026, 5:06 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

6.9

CVSS4.0

CVE-2026-40584 - RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information E…

RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries m…

πŸ“… Published: April 21, 2026, 5:05 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.1

CVSS3.1

CVE-2026-41189 - FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `ConversationPolicy`. A user who cannot view a conversation…

πŸ“… Published: April 21, 2026, 5:04 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

4.3

CVSS3.1

CVE-2026-41183 - FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter path still reveal conversations that should be hid…

πŸ“… Published: April 21, 2026, 5 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

9.4

CVSS4.0

CVE-2026-21571 -

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. Β  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/P…

πŸ“… Published: April 21, 2026, 5 p.m. πŸ”„ Last Modified: April 23, 2026, 3:56 a.m.
Total resulsts: 346099
Page 57 of 34,610
Β« previous page Β» next page
Filters