|
4271
|
6.8 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_votin…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-34068
|
2026-04-25 02:10 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4272
|
8.1 |
HIGH
Network
|
sgbett
|
bsv-wallet bsv_ruby_sdk
|
BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier'…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-40070
|
2026-04-25 02:03 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4273
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. A…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40477
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4274
|
9.0 |
CRITICAL
Network
|
thymeleaf
|
thymeleaf
|
Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanism…
|
CWE-917 CWE-1336
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40478
|
2026-04-25 01:58 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4275
|
7.5 |
HIGH
Network
|
monetr
|
monetr
|
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe sig…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40481
|
2026-04-25 01:57 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4276
|
5.3 |
MEDIUM
Network
|
fastapiexpert
|
python-multipart
|
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-40347
|
2026-04-25 01:51 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4277
|
8.8 |
HIGH
Network
|
nextcloud windmill
|
flow windmill
|
Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the …
|
CWE-862
Missing Authorization
|
CVE-2026-22683
|
2026-04-25 01:49 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4278
|
7.5 |
HIGH
Network
|
powerdns
|
dnsdist
|
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released unt…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-33594
|
2026-04-25 01:48 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4279
|
8.8 |
HIGH
Local
|
nsa
|
emissary
|
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /b…
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2026-35582
|
2026-04-25 01:48 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4280
|
8.3 |
HIGH
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST…
|
CWE-352
Origin Validation Error
|
CVE-2026-40925
|
2026-04-25 01:46 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|