|
1051
|
3.3 |
LOW
Local
|
-
|
-
|
A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the execution phase. This implementation flaw…
|
CWE-768
|
CVE-2026-35378
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1052
|
3.3 |
LOW
Local
|
-
|
-
|
A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes the ASCII space char…
|
CWE-684
Incorrect Provision of Specified Functionality
|
CVE-2026-35379
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1053
|
8.1 |
HIGH
Network
|
-
|
-
|
Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-26354
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1054
|
- |
|
-
|
-
|
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are rendered. The vulnerable renderer interp…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3673
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1055
|
- |
|
-
|
-
|
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the gen…
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2026-6019
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1056
|
- |
|
-
|
-
|
An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. The vulnerable formatter i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3837
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1057
|
- |
|
-
|
-
|
Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/d…
|
CWE-94
Code Injection
|
CVE-2026-41134
|
2026-04-23 06:23 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1058
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard sett…
|
CWE-79
Cross-site Scripting
|
CVE-2024-58344
|
2026-04-23 06:22 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1059
|
- |
|
-
|
-
|
OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious valu…
|
CWE-89
SQL Injection
|
CVE-2026-41457
|
2026-04-23 06:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1060
|
- |
|
-
|
-
|
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized acces…
|
CWE-362
Race Condition
|
CVE-2026-41458
|
2026-04-23 06:21 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|