|
101
|
8.5 |
HIGH
Network
|
b3log
|
siyuan
|
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id pa…
New
|
CWE-24
Path Traversal: '../filedir'
|
CVE-2026-40318
|
2026-04-21 01:50 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
8.1 |
HIGH
Network
|
b3log
|
siyuan
|
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generic authentication that accepts pub…
New
|
CWE-285
Improper Authorization
|
CVE-2026-40259
|
2026-04-21 01:49 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
8.4 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.
Update
|
CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data
|
CVE-2026-32162
|
2026-04-21 01:48 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
7.5 |
HIGH
Network
|
apache
|
skywalking
|
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0.
Users are recom…
Update
|
CWE-202
Exposure of Sensitive Information Through Data Queries
|
CVE-2026-30778
|
2026-04-21 01:46 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
8.8 |
HIGH
Network
|
dataease
|
dataease
|
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerT…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40901
|
2026-04-21 01:46 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
8.8 |
HIGH
Network
|
dataease
|
dataease
|
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplie…
New
|
CWE-89
SQL Injection
|
CVE-2026-40900
|
2026-04-21 01:46 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
7.1 |
HIGH
Network
|
apache
|
skywalking_mcp
|
Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP.
This issue affects Apache SkyWalking MCP: 0.1.0.
Users are recommended to upgrade to version 0.2.0, which fixes…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-34476
|
2026-04-21 01:45 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
Update
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-32163
|
2026-04-21 01:44 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
Update
|
CWE-362
Race Condition
|
CVE-2026-32164
|
2026-04-21 01:43 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
6.5 |
MEDIUM
Network
|
dataease
|
dataease
|
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mys…
New
|
CWE-183
Permissive List of Allowed Inputs
|
CVE-2026-40899
|
2026-04-21 01:42 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|