9.3

CVSS4.0

CVE-2026-39382 - dbt has a Command Injection in Reusable Workflow via Unsanitized comment-body Output

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside the reusable workflow dbt-labs/actions/blob/main/.github/workflows/open-issue-in-repo.yml, the prep job uses peter-evans/find-comment to search for an e…

πŸ“… Published: April 7, 2026, 7:56 p.m. πŸ”„ Last Modified: April 16, 2026, 2:57 p.m.

8.5

CVSS4.0

CVE-2026-32863 - Out-of-Bounds Read in sentry_transaction_context_set_operation()

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.Β  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially c…

πŸ“… Published: April 7, 2026, 7:53 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.

5.3

CVSS4.0

CVE-2026-39381 - Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protected via the protectedFields server option. Any aut…

πŸ“… Published: April 7, 2026, 7:51 p.m. πŸ”„ Last Modified: April 15, 2026, 3:57 p.m.

8.5

CVSS4.0

CVE-2026-32862 - Out-of-Bounds Write in ResFileFactory::InitResourceMgr()

There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.Β  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted V…

πŸ“… Published: April 7, 2026, 7:50 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.

5.4

CVSS3.1

CVE-2026-39380 - Open Source Point of Sale has Stored XSS in Stock Location (Configuration)

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied throug…

πŸ“… Published: April 7, 2026, 7:49 p.m. πŸ”„ Last Modified: April 24, 2026, 5:51 p.m.

6.3

CVSS4.0

CVE-2026-39837 - Stored XSS through the dynamic table format in Cargo

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

πŸ“… Published: April 7, 2026, 7:47 p.m. πŸ”„ Last Modified: April 15, 2026, 11:51 p.m.

8.5

CVSS4.0

CVE-2026-32861 - Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass file

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.Β  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted …

πŸ“… Published: April 7, 2026, 7:46 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.

7.5

CVSS3.1

CVE-2026-39376 - FastFeedParser has an infinite redirect loop DoS via meta-refresh chain

FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns an HTML page containing a <meta http-equiv="refresh"> tag, it recursively calls itself with the redirect URL β€” with no depth limit, no visited-URL deduplication, and no redirect c…

πŸ“… Published: April 7, 2026, 7:46 p.m. πŸ”„ Last Modified: April 15, 2026, 4:15 p.m.

6.3

CVSS4.0

CVE-2026-39841 - Stored XSS through list fields on Cargo's page values and Special:CargoTables

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

πŸ“… Published: April 7, 2026, 7:43 p.m. πŸ”„ Last Modified: April 17, 2026, 9:30 a.m.

8.5

CVSS4.0

CVE-2026-32860 - Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvlib file

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW.Β  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .l…

πŸ“… Published: April 7, 2026, 7:42 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.
Total resulsts: 349182
Page 622 of 34,919
Β« previous page Β» next page
Filters