6.9

CVSS4.0

CVE-2026-34217 - SandboxJS has a Sandbox Escape via Prop Object Leak in New Handler

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sandboxjs. The vulnerability allows untrusted sandboxed code to leak internal interpreter objects through the new operator, exposing sandbox scope objects in the scope hierarchy to un…

📅 Published: April 6, 2026, 3:12 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

6.9

CVSS4.0

CVE-2026-34211 - SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion in the restOfExp function and the lispify/lispifyExpr call chain. An attacker can crash any Node.js process that parses untrusted input by supplying deeply nested expressions (e.…

📅 Published: April 6, 2026, 3:10 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

10

CVSS3.1

CVE-2026-34208 - SandboxJS: Sandbox integrity escape

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject). Because this.construc…

📅 Published: April 6, 2026, 3:09 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

7.5

CVSS3.1

CVE-2026-34148 - Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/doc…

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited…

📅 Published: April 6, 2026, 3:06 p.m. 🔄 Last Modified: April 14, 2026, 1:58 a.m.

6.4

CVSS3.1

CVE-2026-33727 - Pi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this is not a direct inter…

📅 Published: April 6, 2026, 3:02 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

8.6

CVSS3.1

CVE-2026-33752 - Redirect-based SSRF leading to internal network access in curl_cffi (with TLS impersonation bypass)

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endp…

📅 Published: April 6, 2026, 3:01 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

7.5

CVSS3.1

CVE-2026-33540 - Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer rea…

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used w…

📅 Published: April 6, 2026, 2:55 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

8.8

CVSS3.1

CVE-2026-33510 - DOM-Based XSS in Homarr /auth/login Redirect

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl), which is passed to redirect and router.push. An attacker can craft a malicious…

📅 Published: April 6, 2026, 2:51 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

6.5

CVSS3.1

CVE-2026-34897 - WordPress Media LIbrary Assistant plugin <= 3.34 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.34.

📅 Published: April 6, 2026, 2:50 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.4

CVSS3.1

CVE-2026-33406 - Pi-hole has a Stored HTML attribute injection

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the /api/config endpoint are placed directly into HTML value="" attributes without escaping in settings-advanced.js, enabl…

📅 Published: April 6, 2026, 2:50 p.m. 🔄 Last Modified: April 14, 2026, 2:04 a.m.
Total resulsts: 345025
Page 255 of 34,503
« previous page » next page
Filters