|
1701
|
4.6 |
MEDIUM
Network
|
-
|
-
|
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML injection vulnerability that allows any authenticated user with standard (non-admin…
|
CWE-80 CWE-116
Basic XSS Improper Encoding or Escaping of Output
|
CVE-2026-33657
|
2026-04-18 00:38 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1702
|
8.8 |
HIGH
Network
|
-
|
-
|
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a fu…
|
CWE-269 CWE-639
Improper Privilege Management Authorization Bypass Through User-Controlled Key
|
CVE-2026-38529
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1703
|
8.1 |
HIGH
Network
|
-
|
-
|
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-38530
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1704
|
8.1 |
HIGH
Network
|
-
|
-
|
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanentl…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-38532
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1705
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and acco…
|
CWE-285
Improper Authorization
|
CVE-2026-38533
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1706
|
4.9 |
MEDIUM
Network
|
-
|
-
|
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature …
|
CWE-284 CWE-693
Improper Access Control Protection Mechanism Failure
|
CVE-2026-22692
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1707
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
|
CWE-843
Type Confusion
|
CVE-2025-70023
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1708
|
- |
|
-
|
-
|
A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-0207
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1709
|
- |
|
-
|
-
|
Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.
|
CWE-783
Operator Precedence Logic Error
|
CVE-2026-0209
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1710
|
- |
|
-
|
-
|
October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24906
|
2026-04-18 00:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|