0

CVSS3.1

CVE-2026-41144 - Fยด (F Prime) has Integer Overflow in FileUplink

Fยด (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An attacker-crafted DataPacket with byteOffset=0xFFโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:58 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

5.5

CVSS4.0

CVE-2026-41136 - free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-โ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:54 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:39 p.m.

7.5

CVSS3.1

CVE-2026-41135 - free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service

free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability in versions prior to 1.4.3 allows any unauthenticated attacker with network access to the PCF SBI interface to cause uncontrolled memory โ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:49 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:41 p.m.

6.9

CVSS4.0

CVE-2026-40343 - free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creatiโ€ฆ

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.2, a fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continueโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:47 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 7:44 p.m.

8.8

CVSS3.1

CVE-2026-41133 - pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the databasโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:41 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:23 p.m.

5

CVSS3.1

CVE-2026-41131 - OpenFGA has Improper Policy Enforcement

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result forโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:38 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 1:44 p.m.

5.5

CVSS4.0

CVE-2026-41130 - Craft CMS has a host header injection leading to SSRF via resource-js endpoint

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default coโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:36 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.5

CVSS4.0

CVE-2026-41129 - Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" aโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:34 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.3

CVSS4.0

CVE-2026-41128 - Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it perforโ€ฆ

๐Ÿ“… Published: April 21, 2026, 11:32 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-41127 - BigBlueButton's missing authorization allows viewer to inject/overwrite captions

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.

๐Ÿ“… Published: April 21, 2026, 11:24 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:26 p.m.
Total resulsts: 346621
Page 90 of 34,663
ยซ previous page ยป next page
Filters