9.8

CVSS3.1

CVE-2025-70023 -

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 8:30 a.m.

2.7

CVSS3.1

CVE-2026-37602 - SQL Injection in SourceCodester Patient Appointment Scheduler System v1.0

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:31 p.m.

9.8

CVSS3.1

CVE-2025-61260 - OpenAI Codex CLI Arbitrary Command Execution via Malicious Configuration Files

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malicious or compromised repository. Codex automatically loads pr…

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 1:16 p.m.

8.1

CVSS3.1

CVE-2026-38532 - Webkul Krayin CRM v2.2.x BOLA Enables Authenticated Users to Read, Modify, or Delete Other Users' C…

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:03 p.m.

2.7

CVSS3.1

CVE-2026-37598 - Arbitrary Code Execution via Unvalidated Settings Update in Patient Appointment Scheduler System

SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/classes/SystemSettings.php?f=update_settings.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 2:45 a.m.

8.8

CVSS3.1

CVE-2026-38529 - Broken Object-Level Authorization Allows Authenticated Password Reset and Account Takeover

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.

πŸ“… Published: April 14, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 10:30 p.m.

8.7

CVSS4.0

CVE-2026-35469 - SpdyStream: DOS on CRI

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in…

πŸ“… Published: April 13, 2026, 11:59 p.m. πŸ”„ Last Modified: April 17, 2026, 3 a.m.

5.3

CVSS3.1

CVE-2026-34069 - nimiq-consensus panics via RequestMacroChain micro-block locator

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause the RequestMacroChain message handler task to panic. Sending a RequestMacroChain message where the fir…

πŸ“… Published: April 13, 2026, 11:55 p.m. πŸ”„ Last Modified: April 14, 2026, 12:16 a.m.

2.9

CVSS4.0

CVE-2026-33948 - jq: Embedded-NUL Truncation in CLI JSON Input Path Causes Prefix-Only Validation of Malformed Input

jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When reading JSON from files or stdin, jq uses strlen() to determine buffer length instead of the actual byte…

πŸ“… Published: April 13, 2026, 11:51 p.m. πŸ”„ Last Modified: April 14, 2026, 4:32 p.m.

7.5

CVSS3.1

CVE-2026-40164 - jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSO…

πŸ“… Published: April 13, 2026, 11:40 p.m. πŸ”„ Last Modified: April 14, 2026, 7:27 p.m.
Total resulsts: 344974
Page 77 of 34,498
Β« previous page Β» next page
Filters