|
3311
|
3.1 |
LOW
Network
|
openbao
|
openbao
|
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` i…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-39388
|
2026-04-24 22:27 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3312
|
7.6 |
HIGH
Network
|
openremote
|
openremote
|
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user wh…
|
CWE-611
XXE
|
CVE-2026-40882
|
2026-04-24 22:24 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3313
|
8.3 |
HIGH
Network
|
rustfs
|
rustfs
|
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions…
|
CWE-862
Missing Authorization
|
CVE-2026-40937
|
2026-04-24 22:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3314
|
7.0 |
HIGH
Network
|
openremote
|
openremote
|
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keycloak realm can call the Manager API to update Keycloak realm roles for users…
|
CWE-284
Improper Access Control
|
CVE-2026-41166
|
2026-04-24 22:10 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3315
|
5.3 |
MEDIUM
Network
|
pypdf_project
|
pypdf
|
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. This requires cross-ref…
|
CWE-834
Excessive Iteration
|
CVE-2026-41168
|
2026-04-24 22:07 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3316
|
5.9 |
MEDIUM
Network
|
leancrypto
|
leancrypto
|
The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms. Prior to version 1.7.1, lc_x509_extract_name_segment() casts size_t vlen to ui…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2026-34610
|
2026-04-24 22:01 |
2026-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3317
|
7.5 |
HIGH
Network
|
saitoha
|
libsixel
|
libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_decode_raw in fromsixel.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14072
|
2026-04-24 21:56 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3318
|
7.5 |
HIGH
Network
|
saitoha
|
libsixel
|
libsixel 1.8.1 tiene una fuga de memoria en sixel_decoder_decode en decoder.c e image_buffer_resize en fromsixel.c y sixel_decode_raw en fromsixel.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14072
|
2026-04-24 21:56 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3319
|
7.5 |
HIGH
Network
|
saitoha
|
libsixel
|
libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14073
|
2026-04-24 21:56 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3320
|
7.5 |
HIGH
Network
|
saitoha
|
libsixel
|
libsixel 1.8.71 tiene una fuga de memoria en sixel_allocator_new en allocator.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-14073
|
2026-04-24 21:56 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|