6.5

CVSS3.1

CVE-2026-35403 - LORIS has potential cross-site scripting in survey_accounts module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user provi…

πŸ“… Published: April 8, 2026, 6:27 p.m. πŸ”„ Last Modified: April 10, 2026, 8:42 p.m.

3.5

CVSS3.1

CVE-2026-35400 - LORIS incorrectly trusts user input in publication module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, an endpoint in the publication module was incorrectly trusting the baseURL submitted by a user's PO…

πŸ“… Published: April 8, 2026, 6:26 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

8.7

CVSS3.1

CVE-2026-35169 - LORIS has potential cross-site scripting in help_editor module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result…

πŸ“… Published: April 8, 2026, 6:24 p.m. πŸ”„ Last Modified: April 9, 2026, 2:21 p.m.

6.3

CVSS3.1

CVE-2026-35165 - LORIS has incorrect access checks in document_repository

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not co…

πŸ“… Published: April 8, 2026, 6:23 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

6.3

CVSS3.1

CVE-2026-34985 - LORIS has incorrect access checks in media module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the b…

πŸ“… Published: April 8, 2026, 6:22 p.m. πŸ”„ Last Modified: April 10, 2026, 8:41 p.m.

5.8

CVSS4.0

CVE-2026-20709 - microcode_ctl: Intel Processors: Escalation of privilege due to default cryptographic key

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high…

πŸ“… Published: April 8, 2026, 6:20 p.m. πŸ”„ Last Modified: April 9, 2026, 8:27 a.m.

5.3

CVSS4.0

CVE-2026-34837 - Zammad is miissing authorization in AI assistance controller for context data used in text tools

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the AI prompt were not checked if they are accessible…

πŸ“… Published: April 8, 2026, 6:20 p.m. πŸ”„ Last Modified: April 8, 2026, 7:25 p.m.

5.3

CVSS4.0

CVE-2026-34782 - Zammad has improper access control in AI assistance controller for text tools

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the REST endpoint POST /api/v1/ai_assistance/text_tools/:id was not checking if a user is privileged to use the text tool, resulting in being able to use it in all situations. This vulnerability is fixed i…

πŸ“… Published: April 8, 2026, 6:18 p.m. πŸ”„ Last Modified: April 9, 2026, 2:22 p.m.

8.7

CVSS4.0

CVE-2026-34724 - Zammad has a server-side template injection leading to RCE via AI Agent

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vulnerability which leads to RCE via AI Agent exists. Impact is limited to environments where an attacker can control or influence type_enrichment_data (typically high-privilege adm…

πŸ“… Published: April 8, 2026, 6:17 p.m. πŸ”„ Last Modified: April 9, 2026, 4:17 p.m.

8.7

CVSS4.0

CVE-2026-34723 - Zammad has incorrect access control in getting_started_controller

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote attackers were able to access the getting started endpoint to get access to sensitive internal entity data, even after the system setup was completed. This vulnerability is fixed in …

πŸ“… Published: April 8, 2026, 6:14 p.m. πŸ”„ Last Modified: April 10, 2026, 8:40 p.m.
Total resulsts: 343919
Page 63 of 34,392
Β« previous page Β» next page
Filters