8.7

CVSS4.0

CVE-2026-27489 - ONNX: Path Traversal via Symlink

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.

📅 Published: April 1, 2026, 5:33 p.m. 🔄 Last Modified: April 8, 2026, 7:57 p.m.

8.6

CVSS3.1

CVE-2026-34445 - ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) directly from an ONNX model file. It didn’t check if th…

📅 Published: April 1, 2026, 5:30 p.m. 🔄 Last Modified: April 15, 2026, 3:08 p.m.

6.3

CVSS3.1

CVE-2026-34397 - himmelblau: NSS fake-primary group lookup reintroduces name collision risk

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before 3.1.1, there is a conditional local privilege escalation vulnerability in an edge-case naming collision. Only authenticated himmelblau users whose map…

📅 Published: April 1, 2026, 5:25 p.m. 🔄 Last Modified: April 15, 2026, 5:14 p.m.

7.5

CVSS3.1

CVE-2026-34376 - PdfDing: Password-protected share bypass via direct serve endpoint

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.0, an access-control vulnerability allows unauthenticated users to retrieve password-protected shared PDFs by directly calling the file-serving endpoint without compl…

📅 Published: April 1, 2026, 5:05 p.m. 🔄 Last Modified: April 8, 2026, 7:57 p.m.

8.2

CVSS3.1

CVE-2026-34236 - Auth0 PHP SDK Insufficient Entropy in Cookie Encryption

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth0 PHP SDK, cookies are encrypted with insufficient entropy, which may result in threat actors brute-forcing the encryption key and forging session coo…

📅 Published: April 1, 2026, 5:04 p.m. 🔄 Last Modified: April 8, 2026, 7:57 p.m.

7.7

CVSS3.1

CVE-2026-34222 - Open WebUI has Broken Access Control in Tool Valves

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.

📅 Published: April 1, 2026, 5:02 p.m. 🔄 Last Modified: April 15, 2026, 3:25 p.m.

9.8

CVSS3.1

CVE-2026-34159 - llama.cpp: Unauthenticated RCE via GRAPH_COMPUTE buffer=0 bypass in llama.cpp RPC backend

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation when a tensor's buffer field is 0. An unauthenticated attacker can read and write arbitrary process memory via crafted GRAPH_COMPUTE messages. Combine…

📅 Published: April 1, 2026, 4:59 p.m. 🔄 Last Modified: April 30, 2026, 7:18 p.m.

7.4

CVSS3.1

CVE-2026-34076 - Clerk JavaScript: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintend…

Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express from versions 2.0.0 to before 2.0.7, @clerk/backend from versions 3.0.0 to before 3.2.3, and @clerk/fastify from versions 3.1.0 to before 3.1.5, the cl…

📅 Published: April 1, 2026, 4:59 p.m. 🔄 Last Modified: April 3, 2026, 4:10 p.m.

8.3

CVSS3.1

CVE-2026-34072 - cronmaster: Middleware authentication bypass enabling unauthorized page access and server-action ex…

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an authentication bypass in middleware allows unauthenticated requests with an invalid session cookie to be treated as authenticated when the middleware’…

📅 Published: April 1, 2026, 4:51 p.m. 🔄 Last Modified: April 3, 2026, 4:10 p.m.

4.8

CVSS3.1

CVE-2026-20090 - Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could ex…

📅 Published: April 1, 2026, 4:34 p.m. 🔄 Last Modified: April 22, 2026, 7:09 p.m.
Total resulsts: 349182
Page 750 of 34,919
« previous page » next page
Filters