|
851
|
4.3 |
MEDIUM
Network
|
fortra
|
goanywhere_managed_file_transfer
|
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-0971
|
2026-04-23 23:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
852
|
8.8 |
HIGH
Network
|
dell
|
powerprotect_dp_series_appliance data_domain_operating_system
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-26944
|
2026-04-23 22:59 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
853
|
5.4 |
MEDIUM
Network
|
fortra
|
goanywhere_managed_file_transfer
|
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0.
Note: The title, details, and description of this CVE were corrected post-publishing.
New
|
CWE-74
Injection
|
CVE-2026-0972
|
2026-04-23 22:47 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
854
|
7.1 |
HIGH
Network
|
openproject
|
openproject
|
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project can inject agenda items into meetings belonging to a…
Update
|
CWE-367 CWE-639
Time-of-check Time-of-use (TOCTOU) Race Condition Authorization Bypass Through User-Controlled Key
|
CVE-2026-40896
|
2026-04-23 22:45 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
855
|
6.5 |
MEDIUM
Network
|
fortra
|
goanywhere_managed_file_transfer
|
User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.
New
|
CWE-74
Injection
|
CVE-2026-1089
|
2026-04-23 22:45 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
856
|
7.5 |
HIGH
Network
|
internlm
|
lmdeploy
|
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language mod…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-33626
|
2026-04-23 22:39 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
857
|
7.5 |
HIGH
Network
|
junrar_project
|
junrar
|
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controll…
Update
|
CWE-22
Path Traversal
|
CVE-2026-41245
|
2026-04-23 22:35 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
858
|
7.5 |
HIGH
Network
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows unauthenticate…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35245
|
2026-04-23 22:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
859
|
7.5 |
HIGH
Local
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35246
|
2026-04-23 22:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
860
|
6.0 |
MEDIUM
Local
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privilege…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35247
|
2026-04-23 22:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|