|
1611
|
8.8 |
HIGH
Network
|
dataease
|
dataease
|
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoint…
|
CWE-89
SQL Injection
|
CVE-2026-33083
|
2026-04-21 01:35 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1612
|
9.8 |
CRITICAL
Network
|
dataease
|
dataease
|
DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST…
|
CWE-89
SQL Injection
|
CVE-2026-33082
|
2026-04-21 01:34 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1613
|
9.1 |
CRITICAL
Network
|
-
|
-
|
An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiter…
|
CWE-521
Weak Password Requirements
|
CVE-2026-6284
|
2026-04-21 01:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1614
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is loaded, as the Jinja2 chat templates are rendered usin…
|
CWE-94
Code Injection
|
CVE-2026-5760
|
2026-04-21 01:16 |
2026-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1615
|
5.8 |
MEDIUM
Local
|
-
|
-
|
In JetBrains Junie before 252.549.29 command execution was possible via malicious project file
|
CWE-77
Command Injection
|
CVE-2026-41153
|
2026-04-21 01:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1616
|
5.4 |
MEDIUM
Network
|
b3log
|
siyuan
|
SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for CVE-2026-33066) enabled the Lute HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2026-40922
|
2026-04-21 01:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1617
|
- |
|
-
|
-
|
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in…
|
CWE-78
OS Command
|
CVE-2026-40499
|
2026-04-21 01:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1618
|
9.3 |
CRITICAL
Local
|
-
|
-
|
NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers with…
|
CWE-20 CWE-269
Improper Input Validation Improper Privilege Management
|
CVE-2026-40317
|
2026-04-21 01:16 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1619
|
7.5 |
HIGH
Network
|
-
|
-
|
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack bu…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-40170
|
2026-04-21 01:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1620
|
7.5 |
HIGH
Network
|
-
|
-
|
Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-31317
|
2026-04-21 01:16 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|