|
1841
|
2.7 |
LOW
Network
|
windmill
|
windmill
|
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6
and below allow non-admin users to obtain Slack OAuth client secrets, whic…
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-26964
|
2026-04-14 09:50 |
2026-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1842
|
2.7 |
LOW
Network
|
windmill
|
windmill
|
Windmill es una plataforma de desarrollo de código abierto para código interno: APIs, trabajos en segundo plano, flujos de trabajo e interfaces de usuario. Las versiones 1.634.6 y anteriores permiten…
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-26964
|
2026-04-14 09:50 |
2026-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1843
|
6.5 |
MEDIUM
Network
|
lfprojects
|
model_context_protocol_servers
|
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that…
|
CWE-22
Path Traversal
|
CVE-2026-27735
|
2026-04-14 09:44 |
2026-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1844
|
6.5 |
MEDIUM
Network
|
lfprojects
|
model_context_protocol_servers
|
Servidores de Protocolo de Contexto de Modelo es una colección de implementaciones de referencia para el protocolo de contexto de modelo (MCP). En versiones de mcp-server-git anteriores a 2026.1.14, …
|
CWE-22
Path Traversal
|
CVE-2026-27735
|
2026-04-14 09:44 |
2026-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1845
|
7.5 |
HIGH
Network
|
lfprojects
|
mcp_go_sdk
|
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON ke…
|
CWE-178 CWE-436
Improper Handling of Case Sensitivity Interpretation Conflict
|
CVE-2026-27896
|
2026-04-14 09:40 |
2026-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1846
|
7.5 |
HIGH
Network
|
lfprojects
|
mcp_go_sdk
|
El SDK de Go MCP utilizaba la función estándar `encoding/json.Unmarshal` de Go para el análisis de mensajes del protocolo JSON-RPC y MCP en versiones anteriores a la 1.3.1. La biblioteca estándar de …
|
CWE-178 CWE-436
Improper Handling of Case Sensitivity Interpretation Conflict
|
CVE-2026-27896
|
2026-04-14 09:40 |
2026-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1847
|
7.8 |
HIGH
Local
|
google
|
web_designer
|
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
|
CWE-22
Path Traversal
|
CVE-2026-3223
|
2026-04-14 09:33 |
2026-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1848
|
7.8 |
HIGH
Local
|
google
|
web_designer
|
Escritura arbitraria de archivos y potencial escalada de privilegios explotando la vulnerabilidad zip slip en Google Web Designer.
|
CWE-22
Path Traversal
|
CVE-2026-3223
|
2026-04-14 09:33 |
2026-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1849
|
9.8 |
CRITICAL
Network
|
nestjs
|
nest
|
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue affects nest.Js: 11.…
|
CWE-863
Incorrect Authorization
|
CVE-2026-2293
|
2026-04-14 09:30 |
2026-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1850
|
9.8 |
CRITICAL
Network
|
nestjs
|
nest
|
Una aplicación NestJS que utiliza @nestjs/platform-fastify puede permitir la omisión del middleware de autenticación/autorización cuando las opciones de normalización de rutas de Fastify están habili…
|
CWE-863
Incorrect Authorization
|
CVE-2026-2293
|
2026-04-14 09:30 |
2026-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|