7.5

CVSS3.1

CVE-2026-23869 - react-server-dom-parcel: react-server-dom-turbopack: react-server-dom-webpack: denial of service vi…

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered …

πŸ“… Published: April 8, 2026, 7:11 p.m. πŸ”„ Last Modified: April 13, 2026, 2:25 p.m.

7.3

CVSS3.1

CVE-2026-35455 - immich has Stored XSS via OCR Text in 360Β° Panorama Viewer

immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360Β° panorama viewer allows any authenticated user to execute arbitrary JavaScript in the browser of any other user who views the malicious panorama with the OCR o…

πŸ“… Published: April 8, 2026, 6:31 p.m. πŸ”„ Last Modified: April 15, 2026, 6:38 p.m.

7.7

CVSS3.1

CVE-2026-35446 - LORIS has a path traversal in FilesDownloadHandler

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping t…

πŸ“… Published: April 8, 2026, 6:28 p.m. πŸ”„ Last Modified: April 21, 2026, 8:04 p.m.

6.5

CVSS3.1

CVE-2026-35403 - LORIS has potential cross-site scripting in survey_accounts module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user provi…

πŸ“… Published: April 8, 2026, 6:27 p.m. πŸ”„ Last Modified: April 21, 2026, 8:06 p.m.

3.5

CVSS3.1

CVE-2026-35400 - LORIS incorrectly trusts user input in publication module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, an endpoint in the publication module was incorrectly trusting the baseURL submitted by a user's PO…

πŸ“… Published: April 8, 2026, 6:26 p.m. πŸ”„ Last Modified: April 21, 2026, 8:13 p.m.

8.7

CVSS3.1

CVE-2026-35169 - LORIS has potential cross-site scripting in help_editor module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result…

πŸ“… Published: April 8, 2026, 6:24 p.m. πŸ”„ Last Modified: April 21, 2026, 8:16 p.m.

6.3

CVSS3.1

CVE-2026-35165 - LORIS has incorrect access checks in document_repository

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not co…

πŸ“… Published: April 8, 2026, 6:23 p.m. πŸ”„ Last Modified: April 21, 2026, 8:18 p.m.

6.3

CVSS3.1

CVE-2026-34985 - LORIS has incorrect access checks in media module

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the b…

πŸ“… Published: April 8, 2026, 6:22 p.m. πŸ”„ Last Modified: April 21, 2026, 8:20 p.m.

5.8

CVSS4.0

CVE-2026-20709 - microcode_ctl: Intel Processors: Escalation of privilege due to default cryptographic key

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high…

πŸ“… Published: April 8, 2026, 6:20 p.m. πŸ”„ Last Modified: April 10, 2026, 9:40 a.m.

5.3

CVSS4.0

CVE-2026-34837 - Zammad is miissing authorization in AI assistance controller for context data used in text tools

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, he REST endpoint POST /api/v1/ai_assistance/text_tools/:id contains an authorization failure. Context data (e.g., a group or organization) supplied to be used in the AI prompt were not checked if they are accessible…

πŸ“… Published: April 8, 2026, 6:20 p.m. πŸ”„ Last Modified: April 17, 2026, 3:51 p.m.
Total resulsts: 349182
Page 582 of 34,919
Β« previous page Β» next page
Filters