7.5

CVSS3.1

CVE-2026-34020 - Apache OpenMeetings: Login Credentials Passed via GET Query Parameters

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint uses HTTP GET method with username and password passed as query parameters.ย Please check references regarding possible impact This issue affects Apache OpenMeetings: from 3.1.3 beโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 3:21 p.m.

7.8

CVSS3.1

CVE-2026-39853 - osslsigncode has a Stack Buffer Overflow via Unbounded Digest Copy During Signature Verification

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7 signature, the code copies the digest value from a parsed SpcIndirectDatโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:50 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:03 p.m.

7.7

CVSS3.1

CVE-2026-39843 - Plane has a Server-Side Request Forgery (SSRF) in Favicon Fetching

Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw is incomplete which could lead to the same full read Server-Side Request Forgery when a normal html page contains a link tag with an href that redirects to a private IP address isโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:43 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:08 p.m.

5.3

CVSS4.0

CVE-2026-39941 - ChurchCRM has an XSS vulnerability

ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied input sent via a the EName and EDesc parameters in EditEventAttendees.php to be rendered in a page without proper output encoding, enabling arbitrary JavaScript execution in victims' โ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:36 p.m.

5.3

CVSS4.0

CVE-2026-5960 - code-projects Patient Record Management System SQL Database Backup File hcpms.sql information disclโ€ฆ

A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /db/hcpms.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:15 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:02 p.m.

8.4

CVSS4.0

CVE-2026-35205 - Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (.prov file) when signature verification is required. This vulnerability is fixed in 4.1.4.

๐Ÿ“… Published: April 9, 2026, 3:06 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:05 p.m.

2.7

CVSS4.0

CVE-2025-14551 - Senstive information disclosure was affecting subiquity

In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as the user's plaintext Wi-Fi password, in the attached logs.

๐Ÿ“… Published: April 9, 2026, 3:03 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:17 p.m.

8.4

CVSS4.0

CVE-2026-35204 - Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugโ€ฆ

Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location. To prevent this, validate that the plugin.yaml of the Helm plugin does not iโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:03 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:07 p.m.

2.7

CVSS4.0

CVE-2025-15480 - Senstive information disclosure was affecting ubuntu-desktop-provision

In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the user's password hash in the attached logs.

๐Ÿ“… Published: April 9, 2026, 3:02 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:18 p.m.

4.2

CVSS3.1

CVE-2026-35041 - ReDoS in fast-jwt when using RegExp in allowed* leading to CPU exhaustion during token verification

fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configured using a regular expression. Because the aud claim is attacker-controlled and the library evaluates it against the sโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:55 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 8:15 p.m.
Total resulsts: 346621
Page 311 of 34,663
ยซ previous page ยป next page
Filters