6.9

CVSS4.0

CVE-2026-40584 - RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information E…

RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries m…

📅 Published: April 21, 2026, 5:05 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

7.1

CVSS3.1

CVE-2026-41189 - FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `ConversationPolicy`. A user who cannot view a conversation…

📅 Published: April 21, 2026, 5:04 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

4.3

CVSS3.1

CVE-2026-41183 - FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter path still reveal conversations that should be hid…

📅 Published: April 21, 2026, 5 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

9.4

CVSS4.0

CVE-2026-21571 -

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/P…

📅 Published: April 21, 2026, 5 p.m. 🔄 Last Modified: April 23, 2026, 3:56 a.m.

8.8

CVSS4.0

CVE-2026-40583 - UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.

📅 Published: April 21, 2026, 4:57 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

5.9

CVSS3.1

CVE-2026-40592 - FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In a…

📅 Published: April 21, 2026, 4:57 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

7.1

CVSS3.1

CVE-2026-40591 - FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Custo…

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the backend without enforcing mailbox-scoped customer vi…

📅 Published: April 21, 2026, 4:54 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

4.3

CVSS3.1

CVE-2026-40590 - FreeScout's Customer AJAX Create Modifies Hidden Existing Customer

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-email validation. If the supplied email already b…

📅 Published: April 21, 2026, 4:52 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

7.6

CVSS3.1

CVE-2026-40589 - FreeScout has Customer Edit Cross-Mailbox Email Takeover

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address already owned by a hidden customer in another mailbox. The server discloses the hidden customer’s name and profile URL in the success f…

📅 Published: April 21, 2026, 4:50 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

9.8

CVSS3.1

CVE-2026-40050 - CrowdStrike LogScale Unauthenticated Path Traversal

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability …

📅 Published: April 21, 2026, 4:48 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.
Total resulsts: 346103
Page 58 of 34,611
« previous page » next page
Filters