|
651
|
5.4 |
MEDIUM
Network
|
openmage
|
magento
|
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-40098
|
2026-04-24 02:46 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
8.8 |
HIGH
Network
|
openmage
|
magento
|
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Pr…
Update
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40488
|
2026-04-24 02:45 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
6.8 |
MEDIUM
Local
|
oracle
|
financial_services_analytical_applications_infrastructure
|
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affec…
New
|
CWE-284
Improper Access Control
|
CVE-2026-34325
|
2026-04-24 01:43 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
6.5 |
MEDIUM
Network
|
oracle
|
life_sciences_inform
|
Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: App Server). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily exploitabl…
New
|
CWE-284
Improper Access Control
|
CVE-2026-34324
|
2026-04-24 01:42 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
6.3 |
MEDIUM
Network
|
oracle
|
life_sciences_inform
|
Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (component: IDM Authentication). Supported versions that are affected are 7.0.1.0 and 7.0.1.1. Easily ex…
New
|
CWE-284
Improper Access Control
|
CVE-2026-34323
|
2026-04-24 01:41 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
4.8 |
MEDIUM
Network
|
oracle
|
financial_services_analytical_applications_infrastructure
|
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affec…
New
|
CWE-285
Improper Authorization
|
CVE-2026-34321
|
2026-04-24 01:41 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
6.8 |
MEDIUM
Network
|
oracle
|
financial_services_analytical_applications_infrastructure
|
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected ar…
New
|
NVD-CWE-noinfo
|
CVE-2026-34314
|
2026-04-24 01:40 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
6.5 |
MEDIUM
Network
|
oracle
|
financial_services_analytical_applications_infrastructure
|
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected ar…
New
|
CWE-200
Information Exposure
|
CVE-2026-34313
|
2026-04-24 01:35 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
9.1 |
CRITICAL
Network
|
freescout
|
freescout
|
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and predictable formula: `md5(APP_KEY + attachment_id + s…
New
|
CWE-330 CWE-340
Use of Insufficiently Random Values Generation of Predictable Numbers or Identifiers
|
CVE-2026-40496
|
2026-04-24 01:32 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
8.1 |
HIGH
Network
|
freescout
|
freescout
|
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `<script>`, `<form>`, `<iframe>`, `<object>` but does NOT st…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40497
|
2026-04-24 01:32 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|