5

CVSS3.1

CVE-2026-41131 - OpenFGA has Improper Policy Enforcement

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for…

πŸ“… Published: April 21, 2026, 11:38 p.m. πŸ”„ Last Modified: April 24, 2026, 1:44 p.m.

5.5

CVSS4.0

CVE-2026-41130 - Craft CMS has a host header injection leading to SSRF via resource-js endpoint

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default co…

πŸ“… Published: April 21, 2026, 11:36 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.5

CVSS4.0

CVE-2026-41129 - Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" a…

πŸ“… Published: April 21, 2026, 11:34 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.3

CVSS4.0

CVE-2026-41128 - Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it perfor…

πŸ“… Published: April 21, 2026, 11:32 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-41127 - BigBlueButton's missing authorization allows viewer to inject/overwrite captions

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.

πŸ“… Published: April 21, 2026, 11:24 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

4.3

CVSS3.1

CVE-2026-41126 - BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds ar…

πŸ“… Published: April 21, 2026, 11:22 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

9.1

CVSS3.1

CVE-2026-40575 - OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header s…

πŸ“… Published: April 21, 2026, 11:20 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

8.2

CVSS3.1

CVE-2026-41059 - OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_…

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of pat…

πŸ“… Published: April 21, 2026, 11:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

8.9

CVSS4.0

CVE-2026-41304 - WWBN AVideo vulnerable to RCE caused by clonesite plugin

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command execute…

πŸ“… Published: April 21, 2026, 11:07 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

9.3

CVSS3.1

CVE-2026-41064 - AVideo has an incomplete fix for CVE-2026-33502 (Command Injection)

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts strings like `httpevil[.]…

πŸ“… Published: April 21, 2026, 11:04 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.
Total resulsts: 346442
Page 73 of 34,645
Β« previous page Β» next page
Filters