5.4

CVSS3.1

CVE-2026-4829 -

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authenticate as other users, including administrators, via reuse of a session code from an external authentication flow.

πŸ“… Published: April 1, 2026, 2:44 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

6.4

CVSS3.1

CVE-2025-13535 - King Addons for Elementor <= 51.1.38 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scr…

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization and output escaping across multiple widgets and features. The…

πŸ“… Published: April 1, 2026, 2:37 p.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

5.6

CVSS4.0

CVE-2026-5271 - Possible to hijack modules in current working directory

pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current working directory.Β As a result, if a user executes a pymanager-generated command (e.g., pip, pytest) from an attacker-controlled directory, a malicious module in that directory…

πŸ“… Published: April 1, 2026, 1:48 p.m. πŸ”„ Last Modified: April 8, 2026, 7:57 p.m.

8.6

CVSS4.0

CVE-2026-34430 - ByteDance DeerFlow LocalSandboxProvider Host Bash Escape

ByteDance Deer-Flow versions prior to commit 92c7a20 containΒ a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers c…

πŸ“… Published: April 1, 2026, 1:34 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

6.9

CVSS4.0

CVE-2026-34999 - OpenViking 0.2.5 < 0.2.14 Bot Proxy Endpoints Allow Unauthenticated Access

OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows remote unauthenticated attackers to access protected bot proxy functionality by sending requests to the POST /bot/v1/chat and POST /bot/v1/chat/stream endpoints. Attackers ca…

πŸ“… Published: April 1, 2026, 1:30 p.m. πŸ”„ Last Modified: April 8, 2026, 7:59 p.m.

7.3

CVSS4.0

CVE-2026-3877 - Reflected Cross-Site Scripting in Dashboard Search

A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered thro…

πŸ“… Published: April 1, 2026, 1:12 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

7.4

CVSS4.0

CVE-2026-0522 - Local File Inclusion in the File Upload/Download Process

A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated attackers to read arbitrary files from the server by manipulating a file's path during its upload. When the file is subsequently downloaded, the file in the attacker controlled path …

πŸ“… Published: April 1, 2026, 1:11 p.m. πŸ”„ Last Modified: April 8, 2026, 7:59 p.m.

9.3

CVSS4.0

CVE-2026-29014 - MetInfo CMS Unauthenticated PHP Code Injection RCE

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve rem…

πŸ“… Published: April 1, 2026, 12:22 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

7.3

CVSS3.1

CVE-2026-22768 -

Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: April 1, 2026, 12:18 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

7.3

CVSS3.1

CVE-2026-22767 -

Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

πŸ“… Published: April 1, 2026, 12:07 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.
Total resulsts: 349182
Page 754 of 34,919
Β« previous page Β» next page
Filters