|
341
|
4.3 |
MEDIUM
Network
|
nodejs
|
node.js
|
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node…
New
|
NVD-CWE-noinfo CWE-295
Improper Certificate Validation
|
CVE-2026-48934
|
2026-06-29 23:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filter crashes (null po…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47204
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343
|
7.5 |
HIGH
Network
|
-
|
-
|
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
New
|
-
|
CVE-2026-46604
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344
|
9.9 |
CRITICAL
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key.…
New
|
CWE-502 CWE-798 CWE-1188 CWE-1392
Deserialization of Untrusted Data Use of Hard-coded Credentials Insecure Default Initialization of Resource Use of Default Credentials
|
CVE-2026-46386
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345
|
5.9 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password…
New
|
CWE-620
Unverified Password Change
|
CVE-2026-44733
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44732
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid accou…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44731
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348
|
8.1 |
HIGH
Network
|
-
|
-
|
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without para…
New
|
CWE-89
SQL Injection
|
CVE-2026-40524
|
2026-06-29 23:16 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349
|
8.8 |
HIGH
Network
|
-
|
-
|
FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal …
New
|
CWE-22
Path Traversal
|
CVE-2026-40521
|
2026-06-29 23:16 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36908
|
2026-06-29 23:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|