|
251
|
6.5 |
MEDIUM
ネットワーク
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks the U…
Update
|
CWE-22
パス・トラバーサル
|
CVE-2026-41062
|
2026-04-25 00:08 |
2026-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
5.4 |
MEDIUM
ネットワーク
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor,…
Update
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2026-41061
|
2026-04-25 00:08 |
2026-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
6.5 |
MEDIUM
ネットワーク
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows a…
Update
|
CWE-918
サーバサイドリクエストフォージェリ
|
CVE-2026-41060
|
2026-04-25 00:08 |
2026-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
8.1 |
HIGH
ネットワーク
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()`…
Update
|
CWE-22
パス・トラバーサル
|
CVE-2026-41058
|
2026-04-25 00:07 |
2026-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
7.1 |
HIGH
ネットワーク
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` …
Update
|
CWE-346
同一生成元ポリシー違反
|
CVE-2026-41057
|
2026-04-25 00:07 |
2026-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
7.8 |
HIGH
ローカル
|
-
|
-
|
radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with …
New
|
CWE-78
OSコマンド・インジェクション
|
CVE-2026-40517
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
8.1 |
HIGH
ネットワーク
|
-
|
-
|
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in Gra…
New
|
CWE-470
クラスまたはコードを選択する外部から制御された入力の使用
|
CVE-2026-41175
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
- |
-
|
-
|
-
|
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires…
New
|
CWE-789
過剰なサイズ値のメモリ割り当て
|
CVE-2026-41312
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
- |
-
|
-
|
-
|
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a…
New
|
CWE-834
過度なイテレーション
|
CVE-2026-41313
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
- |
-
|
-
|
-
|
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires…
New
|
CWE-789
過剰なサイズ値のメモリ割り当て
|
CVE-2026-41314
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
261
|
5.5 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could uploa…
New
|
CWE-434
危険なタイプのファイルの無制限アップロード
|
CVE-2025-36074
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
2.7 |
LOW
ネットワーク
|
-
|
-
|
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.
New
|
CWE-613
不適切なセッション期限
|
CVE-2026-1272
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
4.9 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.
New
|
CWE-840
ビジネスロジックエラー
|
CVE-2026-1274
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
6.5 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr…
New
|
CWE-1284
入力で指定された数量の不適切な検証
|
CVE-2026-1352
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
4.8 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1
New
|
CWE-269
不適切な権限管理
|
CVE-2026-1726
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
9.8 |
CRITICAL
ネットワーク
|
-
|
-
|
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OA…
New
|
CWE-89
SQLインジェクション
|
CVE-2026-29198
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
7.8 |
HIGH
ローカル
|
-
|
-
|
The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCam…
New
|
CWE-427
制御されていない検索パスの要素
|
CVE-2026-32679
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
7.5 |
HIGH
ネットワーク
|
-
|
-
|
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deploy…
New
|
CWE-269
不適切な権限管理
|
CVE-2026-3621
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
7.5 |
HIGH
ネットワーク
|
-
|
-
|
A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system.
New
|
CWE-22
パス・トラバーサル
|
CVE-2026-40062
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
- |
-
|
-
|
-
|
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate …
New
|
CWE-306
重要な機能に対する認証の欠如 解説
|
CVE-2026-41176
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271
|
- |
-
|
-
|
-
|
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinf…
New
|
CWE-78 CWE-306
OSコマンド・インジェクション 重要な機能に対する認証の欠如 解説
|
CVE-2026-41179
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
4.9 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../…
New
|
CWE-22
パス・トラバーサル
|
CVE-2026-4917
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
5.5 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the int…
New
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2026-4918
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
4.8 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended f…
New
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2026-4919
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
6.5 |
MEDIUM
ネットワーク
|
-
|
-
|
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acce…
New
|
CWE-327
不完全、または危険な暗号アルゴリズムの使用
|
CVE-2026-5926
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
7.3 |
HIGH
ネットワーク
|
-
|
-
|
IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due …
New
|
CWE-78
OSコマンド・インジェクション
|
CVE-2026-5935
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
7.5 |
HIGH
ネットワーク
|
-
|
-
|
PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `re…
New
|
CWE-22
パス・トラバーサル
|
CVE-2026-41180
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
5.3 |
MEDIUM
ネットワーク
|
-
|
-
|
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redacti…
New
|
CWE-200 CWE-359 CWE-532
情報漏えい 認可されていないアクターへの個人情報の漏えい ログファイルからの情報漏えい
|
CVE-2026-41182
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
- |
-
|
-
|
-
|
Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to…
New
|
CWE-94
コード・インジェクション
|
CVE-2026-41196
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
- |
-
|
-
|
-
|
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis to preve…
New
|
CWE-184
不完全なブラックリスト
|
CVE-2026-41206
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281
|
- |
-
|
-
|
-
|
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A…
New
|
CWE-22
パス・トラバーサル
|
CVE-2026-41211
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
- |
-
|
-
|
-
|
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but …
New
|
CWE-284
不適切なアクセス制御
|
CVE-2026-41243
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
- |
-
|
-
|
-
|
Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can i…
New
|
CWE-131
正しくないバッファサイズ計算
|
CVE-2026-41197
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
- |
-
|
-
|
-
|
STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scrip…
New
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2026-41200
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
8.8 |
HIGH
ネットワーク
|
-
|
-
|
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability th…
New
|
CWE-78
OSコマンド・インジェクション
|
CVE-2026-41208
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
10.0 |
CRITICAL
ネットワーク
|
-
|
-
|
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on …
New
|
CWE-287 CWE-862 CWE-1188
不適切な認証 認証の欠如 リソースの安全ではないデフォルト値への初期化
|
CVE-2026-41679
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
5.4 |
MEDIUM
ネットワーク
|
-
|
-
|
Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet fe…
New
|
-
|
CVE-2026-3007
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
9.9 |
CRITICAL
ネットワーク
|
-
|
-
|
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against…
New
|
CWE-98
PHP リモートファイルインクルージョン
|
CVE-2026-41228
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
9.1 |
CRITICAL
ネットワーク
|
-
|
-
|
Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single qu…
New
|
CWE-94
コード・インジェクション
|
CVE-2026-41229
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
8.5 |
HIGH
ネットワーク
|
-
|
-
|
Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in …
New
|
CWE-93
CRLF インジェクション
|
CVE-2026-41230
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291
|
7.5 |
HIGH
ネットワーク
|
-
|
-
|
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` pa…
New
|
CWE-59
リンク解釈の問題
|
CVE-2026-41231
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292
|
5.0 |
MEDIUM
ネットワーク
|
-
|
-
|
Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when s…
New
|
CWE-863
不正な認証
|
CVE-2026-41232
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293
|
5.4 |
MEDIUM
ネットワーク
|
-
|
-
|
Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling res…
New
|
CWE-863
不正な認証
|
CVE-2026-41233
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294
|
3.2 |
LOW
ローカル
|
-
|
-
|
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by t…
New
|
CWE-670
常に不適切な制御フローの実装
|
CVE-2026-41988
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295
|
6.7 |
MEDIUM
ローカル
|
-
|
-
|
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
New
|
CWE-787
境界外書き込み
|
CVE-2026-41989
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296
|
4.0 |
MEDIUM
ローカル
|
-
|
-
|
Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.
New
|
CWE-787
境界外書き込み
|
CVE-2026-41990
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297
|
5.1 |
MEDIUM
ローカル
|
-
|
-
|
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in thi…
New
|
CWE-427
制御されていない検索パスの要素
|
CVE-2025-10549
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298
|
7.3 |
HIGH
ローカル
|
-
|
-
|
IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges.
New
|
CWE-427
制御されていない検索パスの要素
|
CVE-2026-34488
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299
|
7.5 |
HIGH
ネットワーク
|
-
|
-
|
GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string.
New
|
CWE-1333
非効率的な正規表現の複雑さ
|
CVE-2026-41040
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300
|
7.5 |
HIGH
ネットワーク
|
-
|
-
|
CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking.
The Crypt::PK::RSA, Crypt::PK::DSA, Crypt::PK::DH, Crypt::PK::ECC, Crypt::PK::Ed25519 and Crypt::PK::X2551…
New
|
CWE-335 CWE-338
PRNGにおけるシードの不正な使用 暗号における脆弱な PRNG の使用
|
CVE-2026-41564
|
2026-04-24 23:50 |
2026-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|