|
1631
|
5.4 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows an atta…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3466
|
2026-04-15 00:39 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1632
|
7.5 |
HIGH
Network
|
mozilla
|
rhino
|
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the to…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-66453
|
2026-04-15 00:39 |
2025-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1633
|
7.3 |
HIGH
Local
|
checkmk
|
checkmk
|
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privilege…
|
CWE-426 CWE-829
Untrusted Search Path Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2025-39666
|
2026-04-15 00:39 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1634
|
5.3 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endp…
|
CWE-200
Information Exposure
|
CVE-2026-35452
|
2026-04-15 00:37 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1635
|
5.3 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status w…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-35450
|
2026-04-15 00:37 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1636
|
7.2 |
HIGH
Network
|
chyrplite
|
chyrp_lite
|
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings p…
|
CWE-22 CWE-73 CWE-434
Path Traversal External Control of File Name or Path Unrestricted Upload of File with Dangerous Type
|
CVE-2026-35174
|
2026-04-15 00:37 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1637
|
6.5 |
MEDIUM
Network
|
chyrplite
|
chyrp_lite
|
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post…
|
CWE-639 CWE-914
Authorization Bypass Through User-Controlled Key Improper Control of Dynamically-Identified Variables
|
CVE-2026-35173
|
2026-04-15 00:36 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1638
|
9.8 |
CRITICAL
Network
|
linuxfoundation
|
kedro
|
Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGING_CONFIG environment variable and loads it without…
|
CWE-94 CWE-502
Code Injection Deserialization of Untrusted Data
|
CVE-2026-35171
|
2026-04-15 00:36 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1639
|
8.8 |
HIGH
Network
|
frappe
|
helpdesk
|
SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.
|
CWE-89
SQL Injection
|
CVE-2025-10655
|
2026-04-15 00:35 |
2025-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1640
|
8.8 |
HIGH
Network
|
lfprojects
|
model_context_protocol_servers
|
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary f…
|
CWE-22
Path Traversal
|
CVE-2025-68143
|
2026-04-15 00:30 |
2025-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|