8.7

CVSS4.0

CVE-2026-39313 - MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP traโ€ฆ

mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the HTTP transport concatenates request body chunks into a string with no size limit. Although a maxMessageSize configuration value exists, it is never enfโ€ฆ

๐Ÿ“… Published: April 16, 2026, 9:24 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:24 p.m.

4.9

CVSS3.1

CVE-2026-34164 - Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService

Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive information including personal data (PII), citizen identifierโ€ฆ

๐Ÿ“… Published: April 16, 2026, 9:17 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:17 p.m.

4.8

CVSS3.1

CVE-2026-33472 - Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-3โ€ฆ

Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the security fix for CVE-2026-32303. The method hardcodes the URI scheme based on port number, causinโ€ฆ

๐Ÿ“… Published: April 16, 2026, 9:12 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:12 p.m.

8.3

CVSS4.0

CVE-2026-40899 - DataEase has an Arbitrary File Read Vulnerability

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter for the illegalParametโ€ฆ

๐Ÿ“… Published: April 16, 2026, 7:48 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:48 p.m.

8.6

CVSS4.0

CVE-2026-33207 - DataEase SQL Injection Vulnerability

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tableName parameter directly into SQL query strings โ€ฆ

๐Ÿ“… Published: April 16, 2026, 7:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9 p.m.

8.6

CVSS4.0

CVE-2026-33122 - DataEase has SQL Injection via Datasource Management

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a datasource update via /de2api/datasource/update, the deTableName field from the โ€ฆ

๐Ÿ“… Published: April 16, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:15 p.m.

7.1

CVSS4.0

CVE-2025-54502 -

Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.

๐Ÿ“… Published: April 16, 2026, 6:46 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:12 p.m.

5.9

CVSS4.0

CVE-2025-54510 -

Missing lock check in AMD Platform Security Processor in AMD EPYCโ„ข 9005 Series CPUs allows a privileged attacker to potentially impact guest confidentiality via local access.

๐Ÿ“… Published: April 16, 2026, 6:44 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:44 p.m.

8.3

CVSS3.1

CVE-2026-6442 - Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface

Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository, causing the CLI agent tโ€ฆ

๐Ÿ“… Published: April 16, 2026, 6:43 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:43 p.m.

5.6

CVSS4.0

CVE-2023-20585 -

Insuffient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised HV to trigger an out of bounds condition without RMP checks resulting in a potential loss of confidential guest integrity.

๐Ÿ“… Published: April 16, 2026, 6:42 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:42 p.m.
Total resulsts: 344914
Page 1 of 34,492
ยป next page
Filters