9.4

CVSS4.0

CVE-2026-21571 -

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. ย  This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/Pโ€ฆ

๐Ÿ“… Published: April 21, 2026, 5 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:56 a.m.

8.8

CVSS4.0

CVE-2026-40583 - UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.

๐Ÿ“… Published: April 21, 2026, 4:57 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

5.9

CVSS3.1

CVE-2026-40592 - FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:57 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

7.1

CVSS3.1

CVE-2026-40591 - FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Custoโ€ฆ

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the backend without enforcing mailbox-scoped customer viโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:54 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

4.3

CVSS3.1

CVE-2026-40590 - FreeScout's Customer AJAX Create Modifies Hidden Existing Customer

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a โ€œCreate a new customerโ€ flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-email validation. If the supplied email already bโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

7.6

CVSS3.1

CVE-2026-40589 - FreeScout has Customer Edit Cross-Mailbox Email Takeover

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address already owned by a hidden customer in another mailbox. The server discloses the hidden customerโ€™s name and profile URL in the success fโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:50 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

9.8

CVSS3.1

CVE-2026-40050 - CrowdStrike LogScale Unauthenticated Path Traversal

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulnerability only requires mitigation by customers that host specific versions of LogScale and does not affect Next-Gen SIEM customers. The vulnerability โ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:48 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

5.7

CVSS4.0

CVE-2026-40570 - FreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Fulโ€ฆ

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` returns complete customer profile data to any authenticated user without verifying mailbox access. An attacker only needs a valid email address to retโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:48 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

9

CVSS3.1

CVE-2026-40569 - FreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email Exfiltration

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesController.php:468` and `connectionOutgoingSave()` at โ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:46 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

9.4

CVSS3.1

CVE-2026-40576 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in excel-mcp-server

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:35 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:17 p.m.
Total resulsts: 346120
Page 60 of 34,612
ยซ previous page ยป next page
Filters