5.3

CVSS4.0

CVE-2026-39401 - Privilege Escalation via update_event Job Output in Cronicle

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processes can include an update_event key in their JSON output. The server applies this directly to the parent event's stored configuration without any authorization check. A low-privileg…

πŸ“… Published: April 7, 2026, 8:24 p.m. πŸ”„ Last Modified: April 15, 2026, 8:23 p.m.

5.3

CVSS4.0

CVE-2026-39400 - Stored XSS via Job HTML/Table Output in Cronicle

Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user with create_events and run_events privileges can inject arbitrary JavaScript through job output fields (html.content, html.title, table.header, table.rows, table.caption). The ser…

πŸ“… Published: April 7, 2026, 8:22 p.m. πŸ”„ Last Modified: April 15, 2026, 8:24 p.m.

9.4

CVSS3.1

CVE-2026-39397 - @delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthent…

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The…

πŸ“… Published: April 7, 2026, 8:09 p.m. πŸ”„ Last Modified: April 15, 2026, 8:29 p.m.

4.3

CVSS3.1

CVE-2026-39395 - Cosign's verify-blob-attestation reports false positive when payload parsing fails

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, t…

πŸ“… Published: April 7, 2026, 8:06 p.m. πŸ”„ Last Modified: April 15, 2026, 3:57 p.m.

6.9

CVSS4.0

CVE-2026-5741 - suvarchal docker-mcp-server HTTP index.ts pull_image os command injection

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried ou…

πŸ“… Published: April 7, 2026, 8 p.m. πŸ”„ Last Modified: April 8, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-39356 - SQL Injection via escapeName() in all Drizzle ORM SQL dialects

Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or bac…

πŸ“… Published: April 7, 2026, 7:58 p.m. πŸ”„ Last Modified: April 15, 2026, 5:19 p.m.

7

CVSS4.0

CVE-2025-14859 - Semtech LR11xx Secure Boot Bypass

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algorithm that is vulnerable to second preimage attacks. An attacker with physical access to the device c…

πŸ“… Published: April 7, 2026, 7:58 p.m. πŸ”„ Last Modified: April 8, 2026, 9:27 p.m.

5.1

CVSS4.0

CVE-2025-14858 - Semtech LR11xx Encrypted Firmware Disclosure

The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validity check command via the SPI interface, the device decrypts the provided encrypted firmware package …

πŸ“… Published: April 7, 2026, 7:57 p.m. πŸ”„ Last Modified: April 8, 2026, 9:27 p.m.

5.4

CVSS4.0

CVE-2025-14857 - Semtech LR11xx Memory Write Access Control Bypass

An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware where the memory write command accessible via the physical SPI interface fails to enforce write protection on the program call stack. An attacker with physical access to the SPI i…

πŸ“… Published: April 7, 2026, 7:56 p.m. πŸ”„ Last Modified: April 8, 2026, 9:27 p.m.

8.5

CVSS4.0

CVE-2026-32864 - Out-of-Bounds Read in mgcore_SH_25_3!aligned_free()

There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.Β  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI fil…

πŸ“… Published: April 7, 2026, 7:56 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.
Total resulsts: 349182
Page 621 of 34,919
Β« previous page Β» next page
Filters