|
711
|
- |
|
-
|
-
|
jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() API in libjq accepts a counted buffer with an explicit length parameter, but its …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-39979
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
712
|
- |
|
-
|
-
|
jq is a command-line JSON processor. Commits before 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b contain a vulnerability where CLI input parsing allows validation bypass via embedded NUL bytes. When read…
|
CWE-20 CWE-170
Improper Input Validation Improper Null Termination
|
CVE-2026-33948
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
713
|
5.3 |
MEDIUM
Network
|
-
|
-
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause th…
|
CWE-617
Reachable Assertion
|
CVE-2026-34069
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
714
|
7.5 |
HIGH
Network
|
-
|
-
|
jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table op…
|
CWE-328 CWE-407
Use of Weak Hash Inefficient Algorithmic Complexity
|
CVE-2026-40164
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
715
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talen…
|
-
|
CVE-2026-6264
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
716
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and below contain a Blind Server Side Request Forgery in the functionality that allow…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-34225
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
717
|
- |
|
-
|
-
|
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template…
|
CWE-200
Information Exposure
|
CVE-2026-34984
|
2026-04-18 00:26 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
718
|
2.7 |
LOW
Network
|
-
|
-
|
SourceCodester Storage Unit Rental Management System v1.0 is vulnerable to SQL Injection in the file /storage/admin/maintenance/manage_storage_unit.php.
|
CWE-89
SQL Injection
|
CVE-2026-37589
|
2026-04-18 00:25 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
719
|
- |
|
-
|
-
|
MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the n…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-13822
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
720
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-pr…
|
CWE-863
Incorrect Authorization
|
CVE-2026-24069
|
2026-04-18 00:24 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|