7.2

CVSS4.0

CVE-2026-40880 - Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but …

📅 Published: April 21, 2026, 7:18 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

6

CVSS4.0

CVE-2026-40874 - mailcow: dockerized missing authorization on Forwarding Hosts delete action

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place when deleting Forwarding Hosts with `/api/v1/delete/fwdhost`. Any authenticated user can call this API. Checks are only applied for edit/add actions,…

📅 Published: April 21, 2026, 7:17 p.m. 🔄 Last Modified: April 22, 2026, 9:02 p.m.

8.9

CVSS4.0

CVE-2026-40873 - mailcow: dockerized vulnerable to stored XSS in Quarantine attachment filenames

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects attachment filenames into HTML without escaping, allowing arbitrary HTML/JS execution. An attacker can deliver an email with a crafted attachment name so …

📅 Published: April 21, 2026, 7:15 p.m. 🔄 Last Modified: April 22, 2026, 9:02 p.m.

9.3

CVSS4.0

CVE-2026-40872 - mailcow: dockerized vulnerable to stored XSS in autodiscover logs email address field

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs render the EMailAddress value (logged as the "user" field) without HTML escaping. By submitting an unauthenticated Autodiscover request with a crafted …

📅 Published: April 21, 2026, 7:14 p.m. 🔄 Last Modified: April 22, 2026, 9:02 p.m.

7.5

CVSS3.1

CVE-2026-40879 - Nest: DoS via Recursive handleData in JsonSocket (TCP Transport)

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() recurses once per message; the buffer shrinks each call. maxBufferSize is never reached; call stack overflows instead. …

📅 Published: April 21, 2026, 7:14 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

7.2

CVSS3.1

CVE-2026-40871 - mailcow: dockerized vulnerable to Second Order SQL Injection in quarantine category via API

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint stores quarantine_category without validation or sanitizatio…

📅 Published: April 21, 2026, 7:12 p.m. 🔄 Last Modified: April 22, 2026, 9:02 p.m.

7.5

CVSS3.1

CVE-2026-40869 - Decidim amendments can be accepted or rejected by anyone

Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is …

📅 Published: April 21, 2026, 7:08 p.m. 🔄 Last Modified: April 23, 2026, 4:08 p.m.

7.5

CVSS3.1

CVE-2026-40870 - Decidim's comments API allows access to all commentable resources

Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission checks. All Decidim instances are impacted that hav…

📅 Published: April 21, 2026, 7:06 p.m. 🔄 Last Modified: April 22, 2026, 9:08 p.m.

4.8

CVSS3.1

CVE-2026-22751 - Spring Security JdbcOneTimeTokenService allows a one-time token to authenticate multiple sessions

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.…

📅 Published: April 21, 2026, 6:30 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

5.1

CVSS4.0

CVE-2026-6745 - Bagisto Custom Scripts cross site scripting

A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may b…

📅 Published: April 21, 2026, 6:30 p.m. 🔄 Last Modified: April 22, 2026, 7 a.m.
Total resulsts: 346187
Page 63 of 34,619
« previous page » next page
Filters