8.1

CVSS3.1

CVE-2026-40070 - bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and i…

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier's signature over the certificate contents. In acquisition_protocol: 'direct', the caller supplies al…

πŸ“… Published: April 9, 2026, 5:26 p.m. πŸ”„ Last Modified: April 24, 2026, 5:03 p.m.

7.5

CVSS3.1

CVE-2026-40069 - bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts

BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus a…

πŸ“… Published: April 9, 2026, 5:22 p.m. πŸ”„ Last Modified: April 13, 2026, 8:11 p.m.

9.3

CVSS4.0

CVE-2026-39987 - marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket…

πŸ“… Published: April 9, 2026, 5:16 p.m. πŸ”„ Last Modified: April 24, 2026, 3:55 a.m.

6.8

CVSS3.1

CVE-2026-39961 - Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource

Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace β€” production database credentials, API keys, …

πŸ“… Published: April 9, 2026, 5:14 p.m. πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

4.3

CVSS3.1

CVE-2026-39985 - LORIS has an open redirect field on login

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, w…

πŸ“… Published: April 9, 2026, 5:08 p.m. πŸ”„ Last Modified: April 22, 2026, 12:24 a.m.

8.6

CVSS3.1

CVE-2026-39983 - FTP Command Injection via CRLF in basic-ftp

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() he…

πŸ“… Published: April 9, 2026, 5:05 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

8.8

CVSS3.1

CVE-2026-39981 - AGiXT has a Path Traversal in safe_join()

AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or …

πŸ“… Published: April 9, 2026, 5:01 p.m. πŸ”„ Last Modified: April 13, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-5970 - FoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injection

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The…

πŸ“… Published: April 9, 2026, 5 p.m. πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.

9.1

CVSS3.1

CVE-2026-39980 - OpenCTI affected by RCE via notifier template

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arbitrary JavaScript in the context of the OpenCTI platform proce…

πŸ“… Published: April 9, 2026, 4:54 p.m. πŸ”„ Last Modified: April 22, 2026, 12:27 a.m.

7.1

CVSS3.1

CVE-2026-39976 - Laravel Passport's TokenGuard Authenticates Unrelated User for Client Credentials Tokens

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value…

πŸ“… Published: April 9, 2026, 4:50 p.m. πŸ”„ Last Modified: April 13, 2026, 3:02 p.m.
Total resulsts: 346616
Page 308 of 34,662
Β« previous page Β» next page
Filters