6.8

CVSS3.1

CVE-2026-40574 - OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claโ€ฆ

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as [email protected]@company.com and โ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:32 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

5.1

CVSS4.0

CVE-2026-6743 - WebSystems WebTOTUM Calendar cross site scripting

A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading the affected componenโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:30 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 11:46 a.m.

3.7

CVSS3.1

CVE-2026-40279 - BACnet Stack: Undefined-behavior signed left shift in `decode_signed32()`

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacnet/bacint.c reconstructs a 32-bit signed integer from four APDU bytes using signed left shifts. When any of the four bytes has bit 7 set (value โ‰ฅ 0x80), the left-shift opโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:29 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.7

CVSS3.1

CVE-2026-40161 - Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverโ€ฆ

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to 1.10.0, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or Pโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:26 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

5.7

CVSS3.1

CVE-2026-35451 - Twenty: Stored XSS via BlockNote FileBlock

Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock component and insufficient server-side inspection of block content, an attacker can inject a javascript: Uโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:22 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:17 p.m.

3.3

CVSS3.1

CVE-2026-29179 - October: Editor Sub-Permission Bypass for Asset and Blueprint File Operations

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend users who were explicitly granted editor access โ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:19 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:08 p.m.

8.2

CVSS3.1

CVE-2026-24189 - Unauthenticated Out-of-Bounds Read in NVIDIA CUDA-Q Endpoint

NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.

๐Ÿ“… Published: April 21, 2026, 4:17 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.7

CVSS3.1

CVE-2026-24177 - Unauthorized API Access Leading to Information Disclosure in NVIDIA KAI Scheduler

NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure.

๐Ÿ“… Published: April 21, 2026, 4:17 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

3.1

CVSS3.1

CVE-2026-27937 - October: Reflected XSS via DataTable Form Widget

October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:17 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:08 p.m.

4.3

CVSS3.1

CVE-2026-24176 - Improper Authorization Enabling Data Tampering via Crossโ€‘Namespace Pod References in NVIDIA KAI Schโ€ฆ

NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering.

๐Ÿ“… Published: April 21, 2026, 4:17 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.
Total resulsts: 346099
Page 59 of 34,610
ยซ previous page ยป next page
Filters