|
2921
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-26180
|
2026-04-24 03:41 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2922
|
8.4 |
HIGH
Local
|
gitlawb
|
openclaude
|
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool…
|
CWE-22 CWE-284
Path Traversal Improper Access Control
|
CVE-2026-35570
|
2026-04-24 03:37 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2923
|
10.0 |
CRITICAL
Network
|
anthropic
|
claude_code
|
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Clau…
|
CWE-22 CWE-61
Path Traversal UNIX Symbolic Link (Symlink) Following
|
CVE-2026-39861
|
2026-04-24 03:36 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2924
|
9.6 |
CRITICAL
Network
|
getqui
|
qui
|
qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials…
|
CWE-942 NVD-CWE-Other
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-30924
|
2026-04-24 03:34 |
2026-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2925
|
9.6 |
CRITICAL
Network
|
getqui
|
qui
|
qui es una interfaz web para gestionar instancias de qBittorrent. Las versiones 1.14.1 e inferiores utilizan una política CORS permisiva que refleja orígenes arbitrarios y también devuelve Access-Con…
|
CWE-942 NVD-CWE-Other
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-30924
|
2026-04-24 03:34 |
2026-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2926
|
7.5 |
HIGH
Network
|
nasm
|
netwide_assembler
|
A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-6067
|
2026-04-24 03:34 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2927
|
5.3 |
MEDIUM
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a …
|
CWE-284 CWE-863
Improper Access Control Incorrect Authorization
|
CVE-2026-40304
|
2026-04-24 03:33 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2928
|
7.5 |
HIGH
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, cou…
|
CWE-400 CWE-789
Uncontrolled Resource Consumption Memory Allocation with Excessive Size Value
|
CVE-2026-40303
|
2026-04-24 03:33 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2929
|
6.1 |
MEDIUM
Network
|
netfoundry
|
zrok
|
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-40302
|
2026-04-24 03:32 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2930
|
7.5 |
HIGH
Network
|
freedom
|
securedrop-client
|
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Se…
|
CWE-36 CWE-73
Absolute Path Traversal External Control of File Name or Path
|
CVE-2026-35465
|
2026-04-24 03:31 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|