6.9

CVSS4.0

CVE-2026-39351 - Frappe allows unrestricted Doctype access via API exploit

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

📅 Published: April 7, 2026, 6:52 p.m. 🔄 Last Modified: April 10, 2026, 7:30 p.m.

6.9

CVSS4.0

CVE-2026-5736 - PowerJob detailPlus Endpoint InstanceController.java sql injection

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQu…

📅 Published: April 7, 2026, 6:45 p.m. 🔄 Last Modified: April 8, 2026, 9:27 p.m.

5.3

CVSS4.0

CVE-2026-5762 - ReportIncident DiscussionTools integration causes slow requests

Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This issue was remediated only on the `master` branch.

📅 Published: April 7, 2026, 6:42 p.m. 🔄 Last Modified: April 9, 2026, 8:28 a.m.

6.9

CVSS4.0

CVE-2026-22711 - Stored XSS through system messages in WikiLove

Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension allows Cross-Site Scripting (XSS).The issue has been remediated on the `master` branch, and in the release branches for MediaWiki versions 1.43, 1.44, and 1.45.

📅 Published: April 7, 2026, 6:39 p.m. 🔄 Last Modified: April 9, 2026, 8:28 a.m.

2.1

CVSS4.0

CVE-2026-39349 - OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts certain sensitive fields with AES in ECB mode, which preserves block-aligned plaintext patterns in ciphertext and enables pattern disclosure against stored data. This vulnerability i…

📅 Published: April 7, 2026, 6:22 p.m. 🔄 Last Modified: April 10, 2026, 7:32 p.m.

5.3

CVSS4.0

CVE-2026-39348 - OrangeHRM is Missing Authorization Checks in AbstractFileController Subclasses Expose Job Specifica…

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source omits authorization on job specification and vacancy attachment download handlers, allowing authenticated low-privilege users to read attachments via direct reference to attachment identifier…

📅 Published: April 7, 2026, 6:21 p.m. 🔄 Last Modified: April 10, 2026, 7:33 p.m.

5.1

CVSS4.0

CVE-2026-39347 - OrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After Completion

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts changes to self-appraisal submissions for administrator users after those submissions have been marked completed, breaking integrity of finalized appraisal records. This vulnerability…

📅 Published: April 7, 2026, 6:20 p.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

5.3

CVSS4.0

CVE-2026-39346 - OrangeHRM has Improper Access Control Allowing Access to Disabled Modules via URL Encoding

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source allowed authenticated users to bypass disabled-module access controls via URL-encoded request paths and access functionality of modules disabled by an administrator. This vulnerability is fix…

📅 Published: April 7, 2026, 6:19 p.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

4.6

CVSS4.0

CVE-2026-39345 - OrangeHRM Affected by Arbitrary File Read via Path Traversal in Email Template Loader

OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source fails to restrict email template file resolution to the intended plugins directory, allowing an authenticated actor who can influence the template path to read arbitrary local files. This vul…

📅 Published: April 7, 2026, 6:17 p.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

9.3

CVSS4.0

CVE-2026-39324 - Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Mars…

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. Thi…

📅 Published: April 7, 2026, 6:13 p.m. 🔄 Last Modified: April 15, 2026, 8:17 p.m.
Total resulsts: 349182
Page 625 of 34,919
« previous page » next page
Filters