|
1331
|
7.5 |
HIGH
Network
|
qluster
|
deepdiff
|
DeepDiff es un proyecto centrado en la Diferencia Profunda y la búsqueda de cualquier dato de Python. Desde la versión 5.0.0 hasta antes de la versión 8.6.2, el des-serializador de pickle _Restricted…
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-33155
|
2026-04-15 03:24 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1332
|
8.1 |
HIGH
Network
|
dynaconf
|
dynaconf
|
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolv…
|
CWE-94 CWE-1336 CWE-78
Code Injection Improper Neutralization of Special Elements Used in a Template Engine OS Command
|
CVE-2026-33154
|
2026-04-15 03:23 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1333
|
8.1 |
HIGH
Network
|
dynaconf
|
dynaconf
|
dynaconf es una herramienta de gestión de configuración para Python. Antes de la versión 3.2.13, Dynaconf es vulnerable a la Inyección de Plantilla del Lado del Servidor (SSTI) debido a la evaluación…
|
CWE-94 CWE-1336 CWE-78
Code Injection Improper Neutralization of Special Elements Used in a Template Engine OS Command
|
CVE-2026-33154
|
2026-04-15 03:23 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1334
|
7.5 |
HIGH
Network
|
socket
|
socket.io-parser
|
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait f…
|
CWE-20 CWE-754 NVD-CWE-noinfo
Improper Input Validation Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-33151
|
2026-04-15 03:22 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1335
|
7.5 |
HIGH
Network
|
socket
|
socket.io-parser
|
Socket.IO es un framework de comunicación de código abierto, en tiempo real, bidireccional y basado en eventos. Antes de las versiones 3.3.5, 3.4.4 y 4.2.6, un paquete de Socket.IO especialmente dise…
|
CWE-20 CWE-754 NVD-CWE-noinfo
Improper Input Validation Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-33151
|
2026-04-15 03:22 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1336
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bi…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-33144
|
2026-04-15 03:21 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1337
|
7.8 |
HIGH
Local
|
gpac
|
gpac
|
GPAC es un framework multimedia de código abierto. Antes del commit 86b0e36, se descubrió una vulnerabilidad de desbordamiento de búfer basado en montículo (escritura) en GPAC MP4Box. La vulnerabilid…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-33144
|
2026-04-15 03:21 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1338
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Ret…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-39572
|
2026-04-15 03:17 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1339
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in AA Web Servant 12 Step Meeting List 12-step-meeting-list allows Retrieve Embedded Sensitive Data.This issue affects 12 Step Meeting …
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-39570
|
2026-04-15 03:17 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1340
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects Dire…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-39566
|
2026-04-15 03:17 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|