7.8

CVSS3.1

CVE-2026-30979 - iccDEV has a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp() triggered with local user interaction causing memory corruption/crash. This vulnerability is fixed in 2.3.1.5.

πŸ“… Published: March 10, 2026, 5:47 p.m. πŸ”„ Last Modified: April 16, 2026, 9:45 a.m.

5.3

CVSS4.0

CVE-2026-3306 - Improper authorization in GitHub Projects allows modification of issue and pull request metadata wi…

An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repository and write access to a project to modify issue and pull request metadata through the project. When adding an item to a project that already existed, column value up…

πŸ“… Published: March 10, 2026, 5:46 p.m. πŸ”„ Last Modified: April 16, 2026, 3:45 a.m.

7.8

CVSS3.1

CVE-2026-30978 - Heap-use-after-free in CIccCmm::AddXform()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-use-after-free in CIccCmm::AddXform() causing invalid vptr dereference and crash. This vulnerability is fixed in 2.3.1.5.

πŸ“… Published: March 10, 2026, 5:46 p.m. πŸ”„ Last Modified: April 16, 2026, 3:45 a.m.

2

CVSS4.0

CVE-2026-30977 - RenderBlocking has Stored XSS in renderblocking-css with Inline Assets mode

RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScript. Prior to 0.1.1, there is Stored XSS in renderblocking-css with Inline Assets mode. $wgRenderBlockingInlineAssets = true and editsitecss user rights are required. This vulnerab…

πŸ“… Published: March 10, 2026, 5:40 p.m. πŸ”„ Last Modified: April 16, 2026, 4 a.m.

8.7

CVSS4.0

CVE-2026-3854 - Remote code execution via git push option injection in GitHub Enterprise Server

An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker with push access to a repository to achieve remote code execution on the instance. During a git push operation, user-supplied push option values were not properly sanitiz…

πŸ“… Published: March 10, 2026, 5:37 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 p.m.

4.6

CVSS3.1

CVE-2026-30974 - Copyparty volflag `nohtml` did not block javascript in svg files

Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embedded JavaScript, which would execute in the contex…

πŸ“… Published: March 10, 2026, 5:37 p.m. πŸ”„ Last Modified: April 16, 2026, 9:45 a.m.

6.5

CVSS3.1

CVE-2026-30973 - Zip Slip arbitrary file write in @appium/support ZIP extraction

Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Prior to 7.0.6, @appium/support contains a ZIP extraction implementation (extractAllTo() via ZipExtractor.extract()) with a path traversal (Zip Slip) check that is non-functional. Th…

πŸ“… Published: March 10, 2026, 5:33 p.m. πŸ”„ Last Modified: May 7, 2026, 8:46 p.m.

8.8

CVSS4.0

CVE-2026-30970 - Session authentication bypass in Coral Server session creation endpoint

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server allowed the creation of agent sessions through the /api/v1/sessions endpoint without strong authentication. This endpoint performs …

πŸ“… Published: March 10, 2026, 5:30 p.m. πŸ”„ Last Modified: April 16, 2026, 4 a.m.

7.6

CVSS4.0

CVE-2026-30969 - Coral Server has insufficient agent authentication in session communication channels

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server did not enforce strong authentication between agents and the server within an active session. This could allow an attacker who obta…

πŸ“… Published: March 10, 2026, 5:27 p.m. πŸ”„ Last Modified: April 16, 2026, 4 a.m.

8.6

CVSS4.0

CVE-2026-30968 - Coral Server has insufficient validation of agent identity for SSE connections

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a connecting agent was a legitimate participant in the session. Th…

πŸ“… Published: March 10, 2026, 5:24 p.m. πŸ”„ Last Modified: April 16, 2026, 9:45 a.m.
Total resulsts: 349182
Page 1211 of 34,919
Β« previous page Β» next page
Filters