|
321
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers…
Update
|
CWE-403
Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')
|
CVE-2026-40042
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
322
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low-privilege users to escalate privileges by manipulating the original_username c…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40043
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
323
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write P…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40044
|
2026-04-18 00:28 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
324
|
- |
|
-
|
-
|
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users w…
Update
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-32270
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
325
|
- |
|
-
|
-
|
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allo…
Update
|
CWE-89
SQL Injection
|
CVE-2026-32271
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
326
|
- |
|
-
|
-
|
Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct propertie…
Update
|
CWE-89
SQL Injection
|
CVE-2026-32272
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
327
|
3.5 |
LOW
Network
|
-
|
-
|
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Attachment/fromImageUrl endpoint is vulnerable to Server-Side Request Forgery (SS…
Update
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-33659
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
328
|
5.4 |
MEDIUM
Network
|
-
|
-
|
EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Email/importEml endpoint contains an Insecure Direct Object Reference (IDOR) vuln…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-33740
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
329
|
5.3 |
MEDIUM
Network
|
-
|
-
|
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-189 and 6.9.13-44, when `Magick` parses an XML file it is possible that a single…
Update
|
CWE-122 CWE-191
Heap-based Buffer Overflow Integer Underflow (Wrap or Wraparound)
|
CVE-2026-33899
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
330
|
5.9 |
MEDIUM
Network
|
-
|
-
|
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparoun…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-33900
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|