5.3

CVSS3.1

CVE-2026-5380 - runZero Platform cleartext secret exposure

An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Mediu…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 21, 2026, 3:34 p.m.

3

CVSS3.1

CVE-2026-5379 - runZero Platform MCP certification information leak

An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue wa…

πŸ“… Published: April 7, 2026, 2:11 p.m. πŸ”„ Last Modified: April 21, 2026, 3:33 p.m.

5.8

CVSS3.1

CVE-2026-5378 - runZero Platform user creation leak

An issue that allowed administrators to create and update users outside of their authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (5.8 Medium). This issue was fix…

πŸ“… Published: April 7, 2026, 2:11 p.m. πŸ”„ Last Modified: April 21, 2026, 3:31 p.m.

5.9

CVSS3.1

CVE-2026-5376 - runZero Platform session timeout failure

An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolved. This is an instance of CWE-613: Insufficient Control of Resources After Expiration or Release, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N (…

πŸ“… Published: April 7, 2026, 2:11 p.m. πŸ”„ Last Modified: April 21, 2026, 3:22 p.m.

2.7

CVSS3.1

CVE-2026-5375 - runZero Platform API credential information leak

An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to an Unauthorized Actor, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:…

πŸ“… Published: April 7, 2026, 2:11 p.m. πŸ”„ Last Modified: April 21, 2026, 3:11 p.m.

5.8

CVSS3.1

CVE-2026-5374 - runZero Platform MCP information leak

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). Th…

πŸ“… Published: April 7, 2026, 2:10 p.m. πŸ”„ Last Modified: April 21, 2026, 3:10 p.m.

8.1

CVSS3.1

CVE-2026-5373 - runZero Platform superuser privilege escalation

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version…

πŸ“… Published: April 7, 2026, 2:10 p.m. πŸ”„ Last Modified: April 21, 2026, 3:09 p.m.

6.4

CVSS3.1

CVE-2026-5372 - runZero Platform SQL injection in saved queries

An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U…

πŸ“… Published: April 7, 2026, 2:10 p.m. πŸ”„ Last Modified: April 21, 2026, 3:06 p.m.

8.2

CVSS3.1

CVE-2026-4740 - Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes cl…

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This …

πŸ“… Published: April 7, 2026, 2 p.m. πŸ”„ Last Modified: April 28, 2026, 8:39 p.m.

9.8

CVSS3.1

CVE-2026-20911 - LibRaw: LibRaw: Arbitrary Code Execution via specially crafted file

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“… Published: April 7, 2026, 1:49 p.m. πŸ”„ Last Modified: April 10, 2026, 8:50 p.m.
Total resulsts: 349182
Page 638 of 34,919
Β« previous page Β» next page
Filters