|
531
|
7.5 |
HIGH
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, cou…
Update
|
CWE-400 CWE-789
Uncontrolled Resource Consumption Memory Allocation with Excessive Size Value
|
CVE-2026-40303
|
2026-04-24 03:33 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
6.1 |
MEDIUM
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/…
Update
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-40302
|
2026-04-24 03:32 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
7.5 |
HIGH
Network
|
freedom
|
securedrop-client
|
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Se…
Update
|
CWE-36 CWE-73
Absolute Path Traversal External Control of File Name or Path
|
CVE-2026-35465
|
2026-04-24 03:31 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
9.9 |
CRITICAL
Network
|
linuxfoundation
|
spinnaker
|
Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected arti…
New
|
CWE-94
Code Injection
|
CVE-2026-32613
|
2026-04-24 03:30 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
9.9 |
CRITICAL
Network
|
linuxfoundation
|
spinnaker
|
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the c…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-32604
|
2026-04-24 03:30 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
8.8 |
HIGH
Network
|
lawnchair
|
lawnchair
|
Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code …
New
|
CWE-77
Command Injection
|
CVE-2026-39866
|
2026-04-24 03:26 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
6.5 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_scm_purchasing
|
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allow…
New
|
CWE-284
Improper Access Control
|
CVE-2026-34295
|
2026-04-24 03:25 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
4.3 |
MEDIUM
Network
|
oracle
|
agile_product_lifecycle_management_for_process
|
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. E…
New
|
CWE-200
Information Exposure
|
CVE-2026-34296
|
2026-04-24 03:22 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
8.8 |
HIGH
Network
|
m1k1o
|
neko
|
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative…
New
|
CWE-20 CWE-269 CWE-284 CWE-639 CWE-862
Improper Input Validation Improper Privilege Management Improper Access Control Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-39386
|
2026-04-24 03:21 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
3.5 |
LOW
Network
|
-
|
-
|
The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This al…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4512
|
2026-04-24 03:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|