|
111
|
7.8 |
HIGH
Local
|
-
|
-
|
Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. Thi…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-22619
|
2026-04-16 22:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
112
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
New
|
CWE-843
Type Confusion
|
CVE-2025-70023
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
113
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 …
New
|
CWE-385
Covert Timing Channel
|
CVE-2025-69893
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
114
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affec…
New
|
CWE-89
SQL Injection
|
CVE-2025-65133
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
115
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a us…
New
|
CWE-94
Code Injection
|
CVE-2025-61260
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
116
|
8.1 |
HIGH
Network
|
-
|
-
|
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value
from xcom in the way that could be exploited to allow UI user who had access to modify …
New
|
CWE-94
Code Injection
|
CVE-2025-54550
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
117
|
- |
|
-
|
-
|
Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2025-15621
|
2026-04-16 22:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
118
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that, in customizable analytics dashboards, could have allowed…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-4332
|
2026-04-16 22:00 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
119
|
2.7 |
LOW
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with custom r…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4916
|
2026-04-16 21:59 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
120
|
7.5 |
HIGH
Network
|
-
|
-
|
The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insu…
New
|
CWE-89
SQL Injection
|
CVE-2026-3489
|
2026-04-16 21:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|