0.0

CVE-2026-6221 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

📅 Published: April 13, 2026, 1:34 p.m. 🔄 Last Modified: April 29, 2026, 10:19 p.m.

7.1

CVSS3.1

CVE-2026-34476 - Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server

Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

📅 Published: April 13, 2026, 1:01 p.m. 🔄 Last Modified: April 14, 2026, 4:34 p.m.

8.5

CVSS4.0

CVE-2026-6204 - Authenticated Remote Code Execution via Binary Locations in LibreNMS

LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.

📅 Published: April 13, 2026, 10:56 a.m. 🔄 Last Modified: April 22, 2026, 7:47 p.m.

4.6

CVSS4.0

CVE-2026-2728 - Authenticated Cross‑Site Scripting in LibreNMS showconfig Page

LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.

📅 Published: April 13, 2026, 10:39 a.m. 🔄 Last Modified: April 22, 2026, 7:46 p.m.

5.1

CVSS4.0

CVE-2025-15632 - 1Panel-dev MaxKB MdPreview chat.ts cross site scripting

A vulnerability has been found in 1Panel-dev MaxKB up to 2.4.2. Impacted is an unknown function of the file ui/src/chat.ts of the component MdPreview. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. …

📅 Published: April 13, 2026, 9:30 a.m. 🔄 Last Modified: April 24, 2026, 5:57 p.m.

8.8

CVSS3.1

CVE-2026-35337 - Apache Storm Client: RCE through Unsafe Deserialization via Kerberos TGT Credential Handling

Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering…

📅 Published: April 13, 2026, 9:11 a.m. 🔄 Last Modified: April 15, 2026, 3:54 p.m.

5.4

CVSS3.1

CVE-2026-35565 - Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Storm UI

Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6 Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in …

📅 Published: April 13, 2026, 9:10 a.m. 🔄 Last Modified: April 15, 2026, 3:53 p.m.

9.3

CVSS4.0

CVE-2026-4810 - Remote Code Execution in Google Agent Development Kit (ADK)

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. …

📅 Published: April 13, 2026, 8:35 a.m. 🔄 Last Modified: April 13, 2026, 3:01 p.m.

4

CVSS4.0

CVE-2026-0232 - Cortex XDR Agent: Local Administrator can disable the agent on Windows

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

📅 Published: April 13, 2026, 7:22 a.m. 🔄 Last Modified: April 13, 2026, 3:01 p.m.

2

CVSS4.0

CVE-2026-0233 - Autonomous Digital Experience Manager: Improper validation of ADEM certificate

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

📅 Published: April 13, 2026, 7:17 a.m. 🔄 Last Modified: April 14, 2026, 1:49 p.m.
Total resulsts: 349182
Page 502 of 34,919
« previous page » next page
Filters