|
861
|
- |
|
-
|
-
|
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-…
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-40344
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
862
|
6.2 |
MEDIUM
Local
|
-
|
-
|
In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the pres…
New
|
CWE-269 CWE-732
Improper Privilege Management Incorrect Permission Assignment for Critical Resource
|
CVE-2026-6386
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
863
|
2.7 |
LOW
Network
|
-
|
-
|
Tanium addressed an information disclosure vulnerability in Threat Response.
New
|
CWE-200
Information Exposure
|
CVE-2026-6392
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
864
|
2.7 |
LOW
Network
|
-
|
-
|
Tanium addressed an information disclosure vulnerability in Tanium Server.
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-6408
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
865
|
2.7 |
LOW
Network
|
-
|
-
|
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-6416
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
866
|
- |
|
-
|
-
|
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNS…
New
|
CWE-287
Improper Authentication
|
CVE-2026-41145
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
867
|
- |
|
-
|
-
|
facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value star…
New
|
CWE-400 CWE-835
Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41146
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
868
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
New
|
CWE-89
SQL Injection
|
CVE-2026-6833
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
869
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method.
New
|
CWE-862
Missing Authorization
|
CVE-2026-6834
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
870
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result …
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-6835
|
2026-04-23 06:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|