|
2251
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's au…
|
CWE-352
Origin Validation Error
|
CVE-2026-28741
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2252
|
- |
|
-
|
-
|
@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection header after the proxy has added its own headers via rewriteRequestHeaders. This al…
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2026-33805
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2253
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with a…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-3590
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2254
|
7.1 |
HIGH
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardwar…
|
CWE-59
Link Following
|
CVE-2026-0827
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2255
|
6.7 |
MEDIUM
Local
|
-
|
-
|
A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-1636
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2256
|
7.3 |
HIGH
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-4134
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2257
|
6.6 |
MEDIUM
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file w…
|
CWE-59
Link Following
|
CVE-2026-4135
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2258
|
7.8 |
HIGH
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated p…
|
CWE-88
Argument Injection
|
CVE-2026-4145
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2259
|
8.4 |
HIGH
Local
|
-
|
-
|
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payload…
|
CWE-77
Command Injection
|
CVE-2024-53412
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2260
|
7.5 |
HIGH
Network
|
-
|
-
|
CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-30364
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|