8.7

CVSS3.1

CVE-2026-35576 - ChurchCRM has Stored Cross-Site Scripting (XSS) in Person Properties via PrintView.php

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions patched for CVE-2023-38766 and allows an authenticated user to inject arbitrar…

📅 Published: April 7, 2026, 5:11 p.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

7.3

CVSS3.1

CVE-2026-24156 - Untrusted Data Deserialization in NVIDIA DALI Allows Arbitrary Code Execution

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

📅 Published: April 7, 2026, 5:11 p.m. 🔄 Last Modified: April 9, 2026, 8:24 a.m.

8.4

CVSS4.0

CVE-2026-22682 - OpenHarness Improper Access Control via File Tools

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scop…

📅 Published: April 7, 2026, 5:09 p.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

8

CVSS3.1

CVE-2026-35575 - ChurchCRM has Stored XSS in Group Name

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator …

📅 Published: April 7, 2026, 5:08 p.m. 🔄 Last Modified: April 10, 2026, 9:41 a.m.

6.9

CVSS4.0

CVE-2026-22680 - OpenViking < 0.3.3 Missing Authorization via Task Polling

OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes witho…

📅 Published: April 7, 2026, 5:08 p.m. 🔄 Last Modified: April 15, 2026, 4:30 p.m.

7

CVSS4.0

CVE-2026-35572 - SSRF via Referer header in ChurchCRM allows server-side HTTP/HTTPS requests to arbitrary hosts

ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS requests to arbitrary hosts (SSRF) by supplying a crafted URL in the Referer request header. The server subsequently makes an outbound request to the attacker-controlled domain, co…

📅 Published: April 7, 2026, 5:07 p.m. 🔄 Last Modified: April 10, 2026, 8:58 p.m.

9.1

CVSS3.1

CVE-2026-35573 - ChurchCRM has a Path traversal leads to RCE

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The v…

📅 Published: April 7, 2026, 5:06 p.m. 🔄 Last Modified: April 10, 2026, 8:59 p.m.

7.3

CVSS3.1

CVE-2026-35574 - ChurchCRM has a Stored XSS in Person Profile - Add a Note

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor allows authenticated users with note-adding permissions to execute arbitrary JavaScript code in the context of other users' browsers, including administ…

📅 Published: April 7, 2026, 5:04 p.m. 🔄 Last Modified: April 16, 2026, 5:49 p.m.

4

CVSS3.1

CVE-2026-39316 - CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/print…

📅 Published: April 7, 2026, 5 p.m. 🔄 Last Modified: April 16, 2026, 6:08 p.m.

4

CVSS3.1

CVE-2026-39314 - CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-pass…

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative …

📅 Published: April 7, 2026, 4:59 p.m. 🔄 Last Modified: April 16, 2026, 6:13 p.m.
Total resulsts: 349182
Page 629 of 34,919
« previous page » next page
Filters