|
201
|
9.6 |
CRITICAL
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each…
New
|
CWE-20 CWE-190 CWE-345 CWE-1284
Improper Input Validation Integer Overflow or Wraparound Insufficient Verification of Data Authenticity Improper Validation of Specified Quantity in Input
|
CVE-2026-33471
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
6.8 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_votin…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-34068
|
2026-04-25 02:10 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. A…
Update
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40477
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanism…
Update
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40478
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
7.5 |
HIGH
Network
|
monetr
|
monetr
|
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe sig…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40481
|
2026-04-25 01:57 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
5.3 |
MEDIUM
Network
|
fastapiexpert
|
python-multipart
|
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
Update
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-40347
|
2026-04-25 01:51 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
7.5 |
HIGH
Network
|
powerdns
|
dnsdist
|
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released unt…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-33594
|
2026-04-25 01:48 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
8.8 |
HIGH
Local
|
nsa
|
emissary
|
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /b…
Update
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2026-35582
|
2026-04-25 01:48 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
8.3 |
HIGH
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-40925
|
2026-04-25 01:46 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
5.7 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_cs_student_records
|
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerab…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35241
|
2026-04-25 01:44 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|