|
3971
|
6.5 |
MEDIUM
Network
|
vikunja
|
vikunja
|
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization obj…
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-35594
|
2026-04-24 23:53 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3972
|
6.5 |
MEDIUM
Network
|
praison
|
praisonaiagents
|
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI agents with zero validation. No sc…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40150
|
2026-04-24 23:53 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3973
|
5.5 |
MEDIUM
Network
|
-
|
-
|
IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could uploa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-36074
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3974
|
9.8 |
CRITICAL
Network
|
-
|
-
|
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OA…
|
CWE-89
SQL Injection
|
CVE-2026-29198
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3975
|
7.8 |
HIGH
Local
|
-
|
-
|
The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCam…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-32679
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3976
|
7.5 |
HIGH
Network
|
-
|
-
|
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deploy…
|
CWE-269
Improper Privilege Management
|
CVE-2026-3621
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3977
|
7.5 |
HIGH
Network
|
-
|
-
|
A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system.
|
CWE-22
Path Traversal
|
CVE-2026-40062
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3978
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acce…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-5926
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3979
|
7.3 |
HIGH
Network
|
-
|
-
|
IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due …
|
CWE-78
OS Command
|
CVE-2026-5935
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3980
|
- |
|
-
|
-
|
Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to…
|
CWE-94
Code Injection
|
CVE-2026-41196
|
2026-04-24 23:50 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|