4.3

CVSS3.1

CVE-2026-33118 - Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

📅 Published: April 10, 2026, 9:20 p.m. 🔄 Last Modified: April 10, 2026, 10:16 p.m.

5.4

CVSS3.1

CVE-2026-33119 - Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

📅 Published: April 10, 2026, 9:20 p.m. 🔄 Last Modified: April 10, 2026, 10:16 p.m.

6.3

CVSS4.0

CVE-2026-5724 - Missing Authentication on Streaming gRPC Replication Endpoint

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authorization, but the streaming AdminService/StreamWorkflowReplicationMessages endpoint accepted requests wi…

📅 Published: April 10, 2026, 9:06 p.m. 🔄 Last Modified: April 10, 2026, 9:22 p.m.

5.3

CVSS4.0

CVE-2026-40252 - Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT

FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams by supplying a foreign appId. While the API correctly validates the team token, it does not verify …

📅 Published: April 10, 2026, 8:52 p.m. 🔄 Last Modified: April 10, 2026, 9:16 p.m.

7.2

CVSS3.1

CVE-2026-40242 - Arcane Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. …

📅 Published: April 10, 2026, 8:34 p.m. 🔄 Last Modified: April 10, 2026, 9:16 p.m.

3.7

CVSS3.1

CVE-2026-40194 - phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash…

phpseclib is a PHP secure communications library. Prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on equal-length binary strings in PHP uses memcmp(), which short-circuits…

📅 Published: April 10, 2026, 8:24 p.m. 🔄 Last Modified: April 10, 2026, 9:16 p.m.

6.8

CVSS4.0

CVE-2026-40191 - ClearanceKit has a policy bypass via dual-path Endpoint Security events checking only source path

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's Endpoint Security event handler only checked the source path of dual-path file operations against File Access Authorization (FAA) rules and App Jail poli…

📅 Published: April 10, 2026, 8:19 p.m. 🔄 Last Modified: April 10, 2026, 9:16 p.m.

5.3

CVSS4.0

CVE-2026-39922 - GeoNode < 4.4.5, 5.0.2 SSRF via Service Registration

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Atta…

📅 Published: April 10, 2026, 7:53 p.m. 🔄 Last Modified: April 10, 2026, 8:16 p.m.

5.3

CVSS4.0

CVE-2026-39921 - GeoNode < 4.4.5, 5.0.2 SSRF via Document Upload

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malicious URL via the doc_url parameter during document upload. Atta…

📅 Published: April 10, 2026, 7:52 p.m. 🔄 Last Modified: April 10, 2026, 8:16 p.m.

5.6

CVSS3.1

CVE-2026-40190 - LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in …

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against th…

📅 Published: April 10, 2026, 7:47 p.m. 🔄 Last Modified: April 10, 2026, 8:16 p.m.
Total resulsts: 343935
Page 6 of 34,394
« previous page » next page
Filters