9.3

CVSS4.0

CVE-2019-25714 - Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write…

πŸ“… Published: April 21, 2026, 4:11 p.m. πŸ”„ Last Modified: April 22, 2026, 9:20 p.m.

8.5

CVSS3.1

CVE-2026-40568 - FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature. The sanitization function `Helper::stripDangerousTags()` (`app/Misc/Helper.php:568`) uses an incomplete blocklist of only …

πŸ“… Published: April 21, 2026, 4:08 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

5.8

CVSS3.1

CVE-2026-40567 - FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The name is stored in the database without sanitization and…

πŸ“… Published: April 21, 2026, 4:06 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

6.5

CVSS3.1

CVE-2026-25542 - Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a mat…

πŸ“… Published: April 21, 2026, 4:05 p.m. πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

4.1

CVSS3.1

CVE-2026-40566 - FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX actions `fetch_test` (line 731), `send_test` (line 682), a…

πŸ“… Published: April 21, 2026, 4:04 p.m. πŸ”„ Last Modified: April 22, 2026, 9:10 p.m.

6.1

CVSS3.1

CVE-2026-40565 - FreeScout has Stored XSS / CSS Injection via linkify() β€” Unescaped URL in Anchor href

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getCle…

πŸ“… Published: April 21, 2026, 3:52 p.m. πŸ”„ Last Modified: April 22, 2026, 5:34 p.m.

10

CVSS3.1

CVE-2025-15638 - Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

πŸ“… Published: April 21, 2026, 3:34 p.m. πŸ”„ Last Modified: April 22, 2026, 5:35 p.m.

10

CVSS3.1

CVE-2017-20230 - Storable versions before 3.05 for Perl has a stack overflow

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

πŸ“… Published: April 21, 2026, 3:26 p.m. πŸ”„ Last Modified: April 22, 2026, 5:36 p.m.

5.1

CVSS4.0

CVE-2025-41011 - HTML injection in PHP Point Of Sale

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' …

πŸ“… Published: April 21, 2026, 3:15 p.m. πŸ”„ Last Modified: April 22, 2026, 11:46 a.m.

8.9

CVSS4.0

CVE-2026-40498 - FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in…

πŸ“… Published: April 21, 2026, 3:01 p.m. πŸ”„ Last Modified: April 22, 2026, 5:34 p.m.
Total resulsts: 346107
Page 61 of 34,611
Β« previous page Β» next page
Filters