|
2901
|
6.5 |
MEDIUM
Network
|
hkuds
|
openharness
|
OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /mem…
|
CWE-22
Path Traversal
|
CVE-2026-40503
|
2026-04-24 04:39 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2902
|
5.3 |
MEDIUM
Network
|
fastify
|
fastify-static
|
@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured static…
|
CWE-22
Path Traversal
|
CVE-2026-6410
|
2026-04-24 04:31 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2903
|
7.5 |
HIGH
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the handler for creating or updating Traffic Influence Subscriptions checks whether th…
|
CWE-285 CWE-636
Improper Authorization Not Failing Securely ('Failing Open')
|
CVE-2026-40248
|
2026-04-24 04:20 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2904
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to modify protected pa…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-28825
|
2026-04-24 04:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2905
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
Se abordó un problema de escritura fuera de límites con una comprobación de límites mejorada. Este problema está solucionado en macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Una aplica…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-28825
|
2026-04-24 04:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2906
|
6.5 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerabilit…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40907
|
2026-04-24 04:12 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2907
|
5.3 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user…
|
CWE-200
Information Exposure
|
CVE-2026-40908
|
2026-04-24 04:09 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2908
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26174
|
2026-04-24 04:06 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2909
|
4.6 |
MEDIUM
Physics
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-26175
|
2026-04-24 03:58 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2910
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-26176
|
2026-04-24 03:57 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|