|
1551
|
6.5 |
MEDIUM
Network
|
tandoor
|
recipes
|
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import function…
|
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
|
CVE-2026-27460
|
2026-04-15 02:29 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1552
|
9.6 |
CRITICAL
Network
|
depomo
|
chartbrew
|
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartbrew allows authenticated users to create API data …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-30232
|
2026-04-15 02:26 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1553
|
7.7 |
HIGH
Network
|
depomo
|
chartbrew
|
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.9.0, a cross-tenant authorization bypass exists in Chartbrew …
|
CWE-285
Improper Authorization
|
CVE-2026-32252
|
2026-04-15 02:25 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1554
|
9.8 |
CRITICAL
Network
|
libarchive redhat
|
libarchive hardened_images openshift_container_platform enterprise_linux
|
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially c…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-5121
|
2026-04-15 02:16 |
2026-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1555
|
9.8 |
CRITICAL
Network
|
libarchive redhat
|
libarchive hardened_images openshift_container_platform enterprise_linux
|
Se encontró un fallo en libarchive. En sistemas de 32 bits, existe una vulnerabilidad de desbordamiento de entero en la lógica de asignación de punteros de bloque zisofs. Un atacante remoto puede exp…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-5121
|
2026-04-15 02:16 |
2026-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1556
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parameter to /cgi-bin/cstecgi.cgi.
|
CWE-77
Command Injection
|
CVE-2026-31170
|
2026-04-15 02:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1557
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.
|
CWE-94
Code Injection
|
CVE-2026-30479
|
2026-04-15 02:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1558
|
7.8 |
HIGH
Local
|
-
|
-
|
The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical me…
|
CWE-269
Improper Privilege Management
|
CVE-2026-29923
|
2026-04-15 02:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1559
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the Admin Control Panel icon management functionality.
|
CWE-352
Origin Validation Error
|
CVE-2025-70811
|
2026-04-15 02:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1560
|
8.8 |
HIGH
Network
|
-
|
-
|
Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the authentication mechanism
|
CWE-352
Origin Validation Error
|
CVE-2025-70810
|
2026-04-15 02:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|