5.3

CVSS3.1

CVE-2026-6675 - Responsive Blocks <= 2.2.0 - Unauthenticated Open Email Relay via REST API 'email_to' Parameter

The Responsive Blocks โ€“ Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied โ€ฆ

๐Ÿ“… Published: April 21, 2026, 2:25 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 11:46 a.m.

8.1

CVSS3.1

CVE-2026-40497 - FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltrโ€ฆ

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT strip `<style>` tags. The mailbox signature field is saved via POST /mailbox/settings/{id} and later rโ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:45 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3:37 p.m.

4.5

CVSS3.1

CVE-2026-6058 - Denial of Service via Improper Encoding in Zyxel WRE6505 Web Management Interface

** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the WLAN to cause a denial-of-service (DoS) condition in the web management interface by convincing an authenticโ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:42 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 11:46 a.m.

8.8

CVSS4.0

CVE-2026-40496 - FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brโ€ฆ

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + size)`. Since attachment_id is sequential and size can be brute-forced in a small range, an unauthentโ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:38 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:50 p.m.

7.1

CVSS3.1

CVE-2026-39973 - Apktool: Path Traversal to Arbitrary File Write

Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a sโ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:35 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:56 a.m.

8.4

CVSS4.0

CVE-2026-40250 - OpenEXR has integer overflow in DWA decoder outBufferEnd pointer arithmetic (missed variant of CVE-โ€ฆ

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1040` performs `chan->width * chan->bytes_per_elโ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:33 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:55 a.m.

8.4

CVSS4.0

CVE-2026-40244 - OpenEXR has integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (missed varianโ€ฆ

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, `internal_dwa_compressor.h:1722` performs `curc->width * curc->height` in `โ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:30 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 6:41 p.m.

5.3

CVSS3.1

CVE-2026-39886 - OpenEXR has HTJ2K Signed Integer Overflow in ht_undo_impl()

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Versions 3.4.0 through 3.4.9 have a signed integer overflow vulnerability in OpenEXR's HTJ2K (High-Throughput JPEG 2000) decompression path. The `ht_undo_โ€ฆ

๐Ÿ“… Published: April 21, 2026, 1:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 6:41 p.m.

7.4

CVSS4.0

CVE-2026-39866 - Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml

Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.

๐Ÿ“… Published: April 21, 2026, 1:19 a.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:55 a.m.

7.7

CVSS4.0

CVE-2026-39861 - Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symโ€ฆ

๐Ÿ“… Published: April 21, 2026, 12:56 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 11:15 p.m.
Total resulsts: 346107
Page 69 of 34,611
ยซ previous page ยป next page
Filters