5.5

CVSS4.0

CVE-2026-41136 - free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-…

πŸ“… Published: April 21, 2026, 11:54 p.m. πŸ”„ Last Modified: April 23, 2026, 7:39 p.m.

7.5

CVSS3.1

CVE-2026-41135 - free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service

free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability in versions prior to 1.4.3 allows any unauthenticated attacker with network access to the PCF SBI interface to cause uncontrolled memory …

πŸ“… Published: April 21, 2026, 11:49 p.m. πŸ”„ Last Modified: April 23, 2026, 7:41 p.m.

6.9

CVSS4.0

CVE-2026-40343 - free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creati…

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue…

πŸ“… Published: April 21, 2026, 11:47 p.m. πŸ”„ Last Modified: April 23, 2026, 7:44 p.m.

8.8

CVSS3.1

CVE-2026-41133 - pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the databas…

πŸ“… Published: April 21, 2026, 11:41 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

5

CVSS3.1

CVE-2026-41131 - OpenFGA has Improper Policy Enforcement

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for…

πŸ“… Published: April 21, 2026, 11:38 p.m. πŸ”„ Last Modified: April 24, 2026, 1:44 p.m.

5.5

CVSS4.0

CVE-2026-41130 - Craft CMS has a host header injection leading to SSRF via resource-js endpoint

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default co…

πŸ“… Published: April 21, 2026, 11:36 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.5

CVSS4.0

CVE-2026-41129 - Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" a…

πŸ“… Published: April 21, 2026, 11:34 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.3

CVSS4.0

CVE-2026-41128 - Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it perfor…

πŸ“… Published: April 21, 2026, 11:32 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-41127 - BigBlueButton's missing authorization allows viewer to inject/overwrite captions

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.

πŸ“… Published: April 21, 2026, 11:24 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

4.3

CVSS3.1

CVE-2026-41126 - BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds ar…

πŸ“… Published: April 21, 2026, 11:22 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.
Total resulsts: 346549
Page 83 of 34,655
Β« previous page Β» next page
Filters