4.3

CVSS3.1

CVE-2026-24176 - Improper Authorization Enabling Data Tampering via Crossโ€‘Namespace Pod References in NVIDIA KAI Schโ€ฆ

NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering.

๐Ÿ“… Published: April 21, 2026, 4:17 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.6

CVSS3.1

CVE-2026-26274 - October: Safe Mode Bypass via Twig Database Write Operations

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markupโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:16 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:08 p.m.

4.9

CVSS3.1

CVE-2026-26067 - October: Safe Mode Bypass via CSS Preprocessor Compilers

October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the coโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:16 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:08 p.m.

9.3

CVSS4.0

CVE-2019-25714 - Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can writeโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:11 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:20 p.m.

8.5

CVSS3.1

CVE-2026-40568 - FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox signature feature. The sanitization function `Helper::stripDangerousTags()` (`app/Misc/Helper.php:568`) uses an incomplete blocklist of only โ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:08 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

5.8

CVSS3.1

CVE-2026-40567 - FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The name is stored in the database without sanitization andโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:06 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

6.5

CVSS3.1

CVE-2026-25542 - Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a matโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:05 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

4.1

CVSS3.1

CVE-2026-40566 - FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX actions `fetch_test` (line 731), `send_test` (line 682), aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 4:04 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:10 p.m.

6.1

CVSS3.1

CVE-2026-40565 - FreeScout has Stored XSS / CSS Injection via linkify() โ€” Unescaped URL in Anchor href

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getCleโ€ฆ

๐Ÿ“… Published: April 21, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5:34 p.m.

10

CVSS3.1

CVE-2025-15638 - Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

๐Ÿ“… Published: April 21, 2026, 3:34 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5:35 p.m.
Total resulsts: 346120
Page 62 of 34,612
ยซ previous page ยป next page
Filters