7.4

CVSS3.1

CVE-2026-40585 - blueprintUE: Password Reset Tokens Have No Expiry Window

blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-character CSPRNG token is generated and stored alongside a password_reset_at timestamp. However, the token redemption function findUserIDFromEmailAndToken() queries only for a matching …

📅 Published: April 21, 2026, 5:09 p.m. 🔄 Last Modified: April 22, 2026, 9:16 p.m.

7.1

CVSS3.1

CVE-2026-41190 - FreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft …

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `save_draft` AJAX path is weaker. A direct POST can creat…

📅 Published: April 21, 2026, 5:06 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

6.9

CVSS4.0

CVE-2026-40584 - RansomLook - Improper Filtering of Private Location Entries in API Endpoints Leads to Information E…

RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elements from a list while iterating over it, entries m…

📅 Published: April 21, 2026, 5:05 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

7.1

CVSS3.1

CVE-2026-41189 - FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `ConversationPolicy`. A user who cannot view a conversation…

📅 Published: April 21, 2026, 5:04 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

4.3

CVSS3.1

CVE-2026-41183 - FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter path still reveal conversations that should be hid…

📅 Published: April 21, 2026, 5 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

9.4

CVSS4.0

CVE-2026-21571 -

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center.   This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/P…

📅 Published: April 21, 2026, 5 p.m. 🔄 Last Modified: April 23, 2026, 3:56 a.m.

8.8

CVSS4.0

CVE-2026-40583 - UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.

📅 Published: April 21, 2026, 4:57 p.m. 🔄 Last Modified: April 22, 2026, 9:24 p.m.

5.9

CVSS3.1

CVE-2026-40592 - FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the reply being undone. In a…

📅 Published: April 21, 2026, 4:57 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

7.1

CVSS3.1

CVE-2026-40591 - FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Custo…

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the backend without enforcing mailbox-scoped customer vi…

📅 Published: April 21, 2026, 4:54 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.

4.3

CVSS3.1

CVE-2026-40590 - FreeScout's Customer AJAX Create Modifies Hidden Existing Customer

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-email validation. If the supplied email already b…

📅 Published: April 21, 2026, 4:52 p.m. 🔄 Last Modified: April 22, 2026, 9:10 p.m.
Total resulsts: 346285
Page 76 of 34,629
« previous page » next page
Filters