|
1831
|
- |
|
-
|
-
|
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The z…
|
CWE-120 CWE-131
Classic Buffer Overflow Incorrect Calculation of Buffer Size
|
CVE-2026-27820
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1832
|
7.3 |
HIGH
Local
|
-
|
-
|
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
|
CWE-24
Path Traversal: '../filedir'
|
CVE-2026-41082
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1833
|
8.3 |
HIGH
Network
|
-
|
-
|
Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding spec…
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-6442
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1834
|
4.9 |
MEDIUM
Network
|
-
|
-
|
Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-34164
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1835
|
- |
|
-
|
-
|
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocat…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-35469
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1836
|
- |
|
-
|
-
|
mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the HTTP transport concatenates request body chunks int…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-39313
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1837
|
- |
|
-
|
-
|
My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for unauthenticated users, passes user-supplied argument…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40308
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1838
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2024-58343
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1839
|
6.1 |
MEDIUM
Network
|
-
|
-
|
AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and @adonisjs/core versions pr…
|
CWE-601
Open Redirect
|
CVE-2026-40255
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1840
|
8.6 |
HIGH
Network
|
-
|
-
|
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions …
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-22734
|
2026-04-18 00:38 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|