|
631
|
10.0 |
CRITICAL
Network
|
anthropic
|
claude_code
|
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Clau…
New
|
CWE-22 CWE-61
Path Traversal UNIX Symbolic Link (Symlink) Following
|
CVE-2026-39861
|
2026-04-24 03:36 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
5.3 |
MEDIUM
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a …
Update
|
CWE-284 CWE-863
Improper Access Control Incorrect Authorization
|
CVE-2026-40304
|
2026-04-24 03:33 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
7.5 |
HIGH
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, cou…
Update
|
CWE-400 CWE-789
Uncontrolled Resource Consumption Memory Allocation with Excessive Size Value
|
CVE-2026-40303
|
2026-04-24 03:33 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
6.1 |
MEDIUM
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/…
Update
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-40302
|
2026-04-24 03:32 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
7.5 |
HIGH
Network
|
freedom
|
securedrop-client
|
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Se…
Update
|
CWE-36 CWE-73
Absolute Path Traversal External Control of File Name or Path
|
CVE-2026-35465
|
2026-04-24 03:31 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
9.9 |
CRITICAL
Network
|
linuxfoundation
|
spinnaker
|
Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected arti…
New
|
CWE-94
Code Injection
|
CVE-2026-32613
|
2026-04-24 03:30 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
9.9 |
CRITICAL
Network
|
linuxfoundation
|
spinnaker
|
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the c…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-32604
|
2026-04-24 03:30 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
8.8 |
HIGH
Network
|
lawnchair
|
lawnchair
|
Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code …
New
|
CWE-77
Command Injection
|
CVE-2026-39866
|
2026-04-24 03:26 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
6.5 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_scm_purchasing
|
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allow…
New
|
CWE-284
Improper Access Control
|
CVE-2026-34295
|
2026-04-24 03:25 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
4.3 |
MEDIUM
Network
|
oracle
|
agile_product_lifecycle_management_for_process
|
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. E…
New
|
CWE-200
Information Exposure
|
CVE-2026-34296
|
2026-04-24 03:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|