6.3

CVSS4.0

CVE-2026-23517 - Fleet has an Access Control vulnerability in debug/pprof endpoints

Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3 allowed authenticated users to access debug and profiling endpoints regardless of role. As a result, low-privilege users could view internal server diagnostโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:45 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

8.5

CVSS4.0

CVE-2026-23526 - CVAT vulnerable to privilege escalation of users with staff status

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their permissions, including giving themselves superuser status and joining the admin group, which gives them full access to tโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:40 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

8.6

CVSS4.0

CVE-2026-23516 - CVAT vulnerable to XSS via skeleton SVG images

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.2.0 through 2.54.0, an attacker is able to execute arbitrary JavaScript in a victim user's CVAT UI session, provided that they are able to create a maliciously crafted label in a CVAT task or projeโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:38 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.

8.5

CVSS4.0

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor allowed authenticated staff users or Apps to upload arbitrary files, including malicious HTML and SVG files containing Javascript. Depending on the deployment strategy, these filโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:36 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

7.2

CVSS4.0

CVE-2026-22849 - Saleor lacks proper HTML sanitization in rich text fields

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors to perform stored XSS attacks on dashboards and sโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:31 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

9.3

CVSS4.0

CVE-2026-22822 - External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider,โ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:22 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

5.5

CVSS4.0

CVE-2026-22808 - Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStoragโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:18 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

8.8

CVSS3.1

CVE-2026-22807 - vLLM affected by RCE via auto_map dynamic module loading during model initialization

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_code`, allowing attacker-controlled Python code in a model repโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:13 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

9.7

CVSS3.1

CVE-2026-22793 - 5ire vulnerable to Remote Code Execution (RCE) via ECharts

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the rendereโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4:15 a.m.

9.7

CVSS3.1

CVE-2026-22792 - 5ire vulnerable to Remote Code Execution (RCE)

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML rendering permits untrusted HTML (including on* event attributes) to execute in the renderer context. An attacker can inject an `<img onerror=...>` payload tโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, 8:54 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.
Total resulsts: 347766
Page 1895 of 34,777
ยซ previous page ยป next page
Filters