5.3

CVSS3.1

CVE-2026-33899 - ImageMagick: Heap BufferOverflow write of single zero byte when parsing XML

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds. This issue has been fixed in versions 6.9.13-44 and 7.1.2-1โ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:46 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:20 p.m.

4.8

CVSS4.0

CVE-2026-6219 - aandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injection

A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly โ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:45 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:23 p.m.

5.4

CVSS3.1

CVE-2026-33740 - EspoCRM: Email importEml can import and delete another user's attachment by raw fileId

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vulnerability where the attacker-supplied fileId parameter is used to fetch any attachment directly fromโ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:37 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:04 a.m.

3.5

CVSS3.1

CVE-2026-33659 - EspoCRM: SSRF via DNS Rebinding in Attachment fromImageUrl Endpoint Allows Internal Network Access

EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SSRF) via a DNS rebinding (TOCTOU) condition. Host validation uses dns_get_record() but the actual HTTโ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:32 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:07 a.m.

5.3

CVSS4.0

CVE-2026-6218 - aandrew-me ytDownloader Error Details Panel createTextNode cross site scripting

A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosโ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:30 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:33 p.m.

8.7

CVSS4.0

CVE-2026-32272 - Craft Commerce: Blind SQL Injection via hasVariant/hasProduct

Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix โ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:25 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:26 p.m.

7.7

CVSS4.0

CVE-2026-32271 - Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitโ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:19 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:26 p.m.

5.1

CVSS4.0

CVE-2026-6216 - DbGate SVG Icon String FontIcon.svelte cross site scripting

A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launchedโ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:15 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:23 p.m.

1.7

CVSS4.0

CVE-2026-32270 - Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some cusโ€ฆ

Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the email check fails during an anonymous payment. The JSON erroโ€ฆ

๐Ÿ“… Published: April 13, 2026, 8:08 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:26 p.m.

4.6

CVSS3.1

CVE-2026-33657 - EspoCRM: Stored HTML injection in email notifications about stream notes via unescaped post field

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-administrative) privileges to inject arbitrary HTML into system-generated email notifications by craftingโ€ฆ

๐Ÿ“… Published: April 13, 2026, 7:41 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 12:10 a.m.
Total resulsts: 347806
Page 359 of 34,781
ยซ previous page ยป next page
Filters