7.7

CVSS4.0

CVE-2026-40180 - Zip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper class

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzip() method in ApicurioCodegenWrapper.java extracts ZIP entries without validating that the resolved file path stays within the intended output directo…

πŸ“… Published: April 10, 2026, 7:35 p.m. πŸ”„ Last Modified: April 10, 2026, 7:35 p.m.

6.9

CVSS4.0

CVE-2026-40178 - ajenti.plugin.core has a race conditions in 2FA

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.

πŸ“… Published: April 10, 2026, 7:30 p.m. πŸ”„ Last Modified: April 10, 2026, 7:30 p.m.

9.3

CVSS4.0

CVE-2026-40177 - Password bypass when 2FA is activated

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.

πŸ“… Published: April 10, 2026, 7:29 p.m. πŸ”„ Last Modified: April 10, 2026, 7:29 p.m.

10

CVSS3.1

CVE-2026-40175 - Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMD…

πŸ“… Published: April 10, 2026, 7:23 p.m. πŸ”„ Last Modified: April 10, 2026, 7:23 p.m.

8.2

CVSS3.1

CVE-2026-40168 - Postiz has Server-Side Request Forgery via Redirect Bypass in /api/public/stream

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a resu…

πŸ“… Published: April 10, 2026, 7:20 p.m. πŸ”„ Last Modified: April 10, 2026, 7:20 p.m.

7.7

CVSS3.1

CVE-2026-32252 - Chartbrew Cross-Tenant Template Export and Secret Disclosure in `GET /team/:team_id/template/genera…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew in GET /team/:team_id/template/generate/:project_id. The GET handler calls checkAccess(req, "updateA…

πŸ“… Published: April 10, 2026, 7:17 p.m. πŸ”„ Last Modified: April 10, 2026, 7:17 p.m.

7.8

CVSS4.0

CVE-2026-30232 - Chartbrew has SSRF in API Data Connection - No IP Validation on User-Provided URLs

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data connections with arbitrary URLs. The server fetches these URLs using request-promise without any IP …

πŸ“… Published: April 10, 2026, 7:15 p.m. πŸ”„ Last Modified: April 10, 2026, 7:15 p.m.

6.5

CVSS3.1

CVE-2026-27460 - Tandoor Recipes Affected by Denial of Service via Recipe Import

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly d…

πŸ“… Published: April 10, 2026, 7:09 p.m. πŸ”„ Last Modified: April 10, 2026, 7:09 p.m.

5.3

CVSS3.1

CVE-2026-33737 - Chamilo LMS has an XML External Entity (XXE) Injection

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

πŸ“… Published: April 10, 2026, 7:05 p.m. πŸ”„ Last Modified: April 10, 2026, 7:05 p.m.

6.5

CVSS3.1

CVE-2026-33736 - Chamilo LMS has an Insecure Direct Object Reference (IDOR) - User Data Exposure

Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles) via GET /api/users, including administrator accounts. This vulnerability is fixed in 2.0.0-RC.3.

πŸ“… Published: April 10, 2026, 7:03 p.m. πŸ”„ Last Modified: April 10, 2026, 7:03 p.m.
Total resulsts: 343921
Page 6 of 34,393
Β« previous page Β» next page
Filters