|
1481
|
9.6 |
CRITICAL
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each…
|
CWE-20 CWE-190 CWE-345 CWE-1284
Improper Input Validation Integer Overflow or Wraparound Insufficient Verification of Data Authenticity Improper Validation of Specified Quantity in Input
|
CVE-2026-33471
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1482
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could crash a validator by …
|
CWE-125 CWE-193
Out-of-bounds Read Off-by-one Error
|
CVE-2026-32605
|
2026-04-25 02:11 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1483
|
8.1 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks an…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-40093
|
2026-04-25 02:11 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1484
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause th…
|
CWE-617
Reachable Assertion
|
CVE-2026-34069
|
2026-04-25 02:10 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1485
|
6.8 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_votin…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-34068
|
2026-04-25 02:10 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1486
|
8.1 |
HIGH
Network
|
sgbett
|
bsv-wallet bsv_ruby_sdk
|
BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier'…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-40070
|
2026-04-25 02:03 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1487
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. A…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40477
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1488
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanism…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40478
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1489
|
7.5 |
HIGH
Network
|
monetr
|
monetr
|
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe sig…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40481
|
2026-04-25 01:57 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1490
|
5.3 |
MEDIUM
Network
|
fastapiexpert
|
python-multipart
|
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-40347
|
2026-04-25 01:51 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|