8.7

CVSS4.0

CVE-2026-34833 - Bulwark Webmail: Information Exposure: password returned in /api/auth/session

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has be…

πŸ“… Published: April 2, 2026, 7:11 p.m. πŸ”„ Last Modified: April 10, 2026, 9:45 a.m.

6.5

CVSS3.1

CVE-2026-34832 - Scoold: Cross-Account Feedback Deletion (IDOR)

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The …

πŸ“… Published: April 2, 2026, 7:08 p.m. πŸ”„ Last Modified: April 15, 2026, 5:29 p.m.

8.5

CVSS4.0

CVE-2026-34825 - NocoBase Has SQL Injection via template variable substitution in workflow SQL node

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.30, NocoBase plugin-workflow-sql substitutes template variables directly into raw SQL strings via getParsedValue() without parameterization or escaping. Any user who…

πŸ“… Published: April 2, 2026, 7:06 p.m. πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

6.9

CVSS4.0

CVE-2026-35383 - Bentley Systems iTwin Platform exposed access token

Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated attacker could use this token to enumerate or delete certain assets. As of 2026-03-27, the token is no longer present in the web pages and cannot be used to enumerate or delete asset…

πŸ“… Published: April 2, 2026, 7:04 p.m. πŸ”„ Last Modified: April 14, 2026, 2:04 p.m.

2.7

CVSS3.1

CVE-2026-34762 - Ella Core Has Audit Log Falsification via Path/Body IMSI Mismatch in UpdateSubscriber

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, the PUT /api/v1/subscriber/{imsi} API accepts an IMSI identifier from both the URL path and the JSON request body but never verifies they match. This allows an authenticated NetworkManager to modify any subscriber's polic…

πŸ“… Published: April 2, 2026, 7:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:54 p.m.

5.8

CVSS3.1

CVE-2026-34761 - Ella Core Panics Upon NGAP handover failure

Ella Core is a 5G core designed for private networks. Prior to version 1.8.0, Ella Core panics when processing a NGAP handover failure message. An attacker able to cause a gNodeB to send NGAP handover failure messages to Ella Core can crash the process, causing service disruption for all connected …

πŸ“… Published: April 2, 2026, 7:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:55 p.m.

2

CVSS4.0

CVE-2026-5420 - Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key

A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of hard-coded cryptogra…

πŸ“… Published: April 2, 2026, 7 p.m. πŸ”„ Last Modified: April 24, 2026, 6:13 p.m.

5.9

CVSS3.1

CVE-2026-34760 - vLLM: Downmix Implementation Differences as Attack Vectors Against Audio AI Models

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using numpy.mean for mono downmixing (to_mono), while the international standard ITU-R BS.775-4 specifies a weighted downmixing algorithm. This discrepancy resu…

πŸ“… Published: April 2, 2026, 6:59 p.m. πŸ”„ Last Modified: April 7, 2026, 7:55 a.m.

9.2

CVSS4.0

CVE-2026-35053 - OneUptime: Unauthenticated Workflow Execution via ManualAPI

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflowId) without any authentication middleware. An attacker who ca…

πŸ“… Published: April 2, 2026, 6:55 p.m. πŸ”„ Last Modified: April 14, 2026, 4:41 p.m.

8.1

CVSS3.1

CVE-2026-34840 - OneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature Verification

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSignatureValid() verifies the first <Signature> element in the XML …

πŸ“… Published: April 2, 2026, 6:52 p.m. πŸ”„ Last Modified: April 14, 2026, 4:41 p.m.
Total resulsts: 349182
Page 719 of 34,919
Β« previous page Β» next page
Filters