7.5

CVSS3.1

CVE-2026-40938 - Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leadinโ€ฆ

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to before 1.11.0, the git resolver's revision parameter is passed directly as a positional argument to git fetch without any validation that it does not begin with a - character. Because git parsesโ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:45 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

5.3

CVSS4.0

CVE-2026-6797 - Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption

A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function ZipSecureFile.setMinflateRatio of the file common/src/main/java/com/publiccms/common/tools/DocToHtmlUtils.java. Such manipulation leads to resource consumption. It is possible to lauโ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:45 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5:30 p.m.

9.8

CVSS3.1

CVE-2026-33519 - Incorrect privilege assignment in Portal for ArcGIS

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

๐Ÿ“… Published: April 21, 2026, 8:38 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:56 a.m.

9.8

CVSS3.1

CVE-2026-33518 - Incorrect privilege assignment in Portal for ArcGIS

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.

๐Ÿ“… Published: April 21, 2026, 8:37 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:56 a.m.

8.3

CVSS4.0

CVE-2026-6823 - HKUDS OpenHarness Insecure Default Remote Channel Allowlist

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote senders to pass admission checks. Attackers who can reach the configured channel can bypass access controls and reach โ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:36 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 11:45 a.m.

6.4

CVSS3.1

CVE-2026-35252 - Lowโ€‘Privilege HTTPS Vulnerability in Oracle Security Service Enables Unauthorized Data Modification

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Supported versions that are affected are 12.2.1.4.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle โ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:35 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:24 p.m.

7.5

CVSS3.1

CVE-2026-35251 - Privilege Escalation Leading to VirtualBox Takeover via Local Exploit

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracโ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:35 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 12:57 p.m.

2.3

CVSS3.1

CVE-2026-35250 -

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracleโ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:35 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 12:59 p.m.

3.2

CVSS3.1

CVE-2026-35249 - Local Access Integrity Vulnerability in Oracle VM VirtualBox 7.2.6

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracleโ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:35 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 12:59 p.m.

5

CVSS3.1

CVE-2026-35248 - Privilege Escalation and Partial Denial in Oracle VM VirtualBox 7.2.6

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracโ€ฆ

๐Ÿ“… Published: April 21, 2026, 8:35 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 12:59 p.m.
Total resulsts: 346531
Page 86 of 34,654
ยซ previous page ยป next page
Filters