8.8

CVSS4.0

CVE-2026-39937 - Global vanishing does not completely remove user email

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.ย The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.โ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:44 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 8:28 a.m.

9.1

CVSS3.1

CVE-2026-39847 - Emmett has a path traversal in internal assets handler

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbitrarโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:37 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:31 a.m.

9.1

CVSS3.1

CVE-2026-39846 - SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in synced taโ€ฆ

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:34 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:32 a.m.

6.2

CVSS3.1

CVE-2026-35406 - Aardvark-dns has incorrect error handling for malformed tcp packets

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.

๐Ÿ“… Published: April 7, 2026, 9:32 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:33 a.m.

8.7

CVSS4.0

CVE-2026-34079 - Flatpak affected by arbitrary file deletion on the host filesystem

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on thโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:29 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:26 p.m.

9.3

CVSS4.0

CVE-2026-34078 - Flatpak has a complete sandbox escape leading to host file access and code execution in the host coโ€ฆ

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts the resolved host path in the sandbox. This gives apps access toโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:27 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 5:50 p.m.

5.4

CVSS3.1

CVE-2026-4065 - Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider Data Readโ€ฆ

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (whโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:26 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 9:26 p.m.

2.8

CVSS3.1

CVE-2026-34781 - Electron crashes in clipboard.readImage() on malformed clipboard image data

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system clipboard contains image data that fails to decodโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:20 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 7:34 p.m.

6

CVSS3.1

CVE-2026-34765 - Electron named window.open targets not scoped to the opener's browsing context

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing contโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:18 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 5:12 p.m.

8.7

CVSS4.0

CVE-2026-34582 - Botan has a TLS 1.3 certificate authentication bypass

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entโ€ฆ

๐Ÿ“… Published: April 7, 2026, 9:13 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:31 p.m.
Total resulsts: 349182
Page 619 of 34,919
ยซ previous page ยป next page
Filters