|
2941
|
- |
|
-
|
-
|
Rejected reason: This CVE is a duplicate of another CVE.
|
-
|
CVE-2026-40609
|
2026-04-25 01:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2942
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sched: act_ife: Fix metalist update behavior
Whenever an ife action replace changes the metalist, instead of
replacing the ol…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23378
|
2026-04-25 00:57 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2943
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
net/sched: act_ife: Corregir el comportamiento de actualización de la metalista
Siempre que una acción ife replace cambia la met…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23378
|
2026-04-25 00:57 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2944
|
7.4 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: Compare MACs in constant time
To prevent timing attacks, MAC comparisons need to be constant-time.
Replace the memcmp() wi…
|
NVD-CWE-noinfo
|
CVE-2026-23364
|
2026-04-25 00:46 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2945
|
7.4 |
HIGH
Network
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
ksmbd: Comparar MACs en tiempo constante
Para prevenir ataques de temporización, las comparaciones de MAC necesitan ser de tiemp…
|
NVD-CWE-noinfo
|
CVE-2026-23364
|
2026-04-25 00:46 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2946
|
9.8 |
CRITICAL
Network
|
phpscriptsmall
|
advance_gift_shop_pro_script
|
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parame…
|
CWE-89
SQL Injection
|
CVE-2019-25680
|
2026-04-25 00:45 |
2026-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2947
|
9.8 |
CRITICAL
Network
|
wisdom
|
pegasus_cms
|
Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionali…
|
CWE-22
Path Traversal
|
CVE-2019-25687
|
2026-04-25 00:42 |
2026-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2948
|
5.3 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occ…
|
CWE-346
Origin Validation Error
|
CVE-2026-37977
|
2026-04-25 00:39 |
2026-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2949
|
9.8 |
CRITICAL
Network
|
weaver
|
e-cology
|
Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows att…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-22679
|
2026-04-25 00:31 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2950
|
5.4 |
MEDIUM
Network
|
papra
|
papra
|
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate user.name directly into HTML without escaping or sanitization. …
|
CWE-79 CWE-80
Cross-site Scripting Basic XSS
|
CVE-2026-35460
|
2026-04-25 00:31 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|