6.3

CVSS4.0

CVE-2026-34451 - Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not …

📅 Published: March 31, 2026, 9:35 p.m. 🔄 Last Modified: April 20, 2026, 2:47 p.m.

4.8

CVSS4.0

CVE-2026-34450 - Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Tool

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the local filesystem memory tool in the Anthropic Python SDK created memory files with mode 0o666, leaving them world-readable on systems with a standard umask and wor…

📅 Published: March 31, 2026, 9:32 p.m. 🔄 Last Modified: April 14, 2026, 4:42 p.m.

5.8

CVSS4.0

CVE-2026-34452 - Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local filesystem memory tool in the Anthropic Python SDK validated that model-supplied paths resolved inside the sandboxed memory directory, but then returne…

📅 Published: March 31, 2026, 9:32 p.m. 🔄 Last Modified: April 20, 2026, 1:34 p.m.

5.4

CVSS3.1

CVE-2026-34442 - FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Reso…

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-34443 - FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR …

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 14, 2026, 4:42 p.m.

4.8

CVSS3.1

CVE-2026-34441 - cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive connections, the unread bo…

📅 Published: March 31, 2026, 9:21 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

9.4

CVSS4.0

CVE-2026-34406 - APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edituser/<pk>) allows Any user who can reach that endpoint and sub…

📅 Published: March 31, 2026, 9:18 p.m. 🔄 Last Modified: April 13, 2026, 2:28 p.m.

6.1

CVSS3.1

CVE-2026-34405 - Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributes

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched i…

📅 Published: March 31, 2026, 9:16 p.m. 🔄 Last Modified: April 14, 2026, 4:42 p.m.

6.9

CVSS4.0

CVE-2026-34404 - Nuxt OG Image vulnerable to DoS via image generation

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height pa…

📅 Published: March 31, 2026, 9:16 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

5.3

CVSS4.0

CVE-2026-5215 - D-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cg…

📅 Published: March 31, 2026, 9:15 p.m. 🔄 Last Modified: April 3, 2026, 9:19 a.m.
Total resulsts: 349182
Page 768 of 34,919
« previous page » next page
Filters