|
651
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially le…
Update
|
CWE-200
Information Exposure
|
CVE-2025-52649
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION se ve afectado por una vulnerabilidad donde ciertos identificadores pueden ser predecibles por naturaleza. Los identificadores predecibles pueden permitir a un atacante inferir o adivinar va…
Update
|
CWE-200
Information Exposure
|
CVE-2025-52649
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modifie…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-52645
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
5.3 |
MEDIUM
Network
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad donde los mecanismos de empaquetado y distribución de modelos podrían no incluir suficiente verificación de autenticidad. Esto podría permitir la posibil…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2025-52645
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
7.8 |
HIGH
Local
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security …
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-52643
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
7.8 |
HIGH
Local
|
hcltech
|
aion
|
HCL AION está afectado por una vulnerabilidad donde las operaciones de análisis de archivos no confiables no se ejecutan dentro de un entorno de sandbox debidamente aislado. Esto puede exponer la apl…
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-52643
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-52636
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION se ve afectado por una vulnerabilidad relacionada con el manejo de los límites de tamaño de carga. Un control o validación inadecuados de los tamaños de carga puede permitir un consumo exces…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-52636
|
2026-04-26 03:04 |
2026-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
7.5 |
HIGH
Network
|
fedify
|
fedify\/fedify fedify\/vocab-runtime
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote doc…
Update
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-34148
|
2026-04-26 03:03 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service …
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-21388
|
2026-04-26 03:02 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
661
|
3.7 |
LOW
Network
|
linuxfoundation
|
backstage\/backend_defaults
|
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24048
|
2026-04-26 03:01 |
2026-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
662
|
3.7 |
LOW
Network
|
linuxfoundation
|
backstage\/backend_defaults
|
Backstage es un framework abierto para construir portales de desarrolladores, y @backstage/backend-defaults proporciona las implementaciones y configuración predeterminadas para una aplicación backen…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24048
|
2026-04-26 03:01 |
2026-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
663
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encod…
Update
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
664
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 1.20.1, una vulnerabilidad en el análisis de URL de SCM utilizado por las integraciones de Backstage …
Update
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
665
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run throug…
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
666
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 3.1.4, una plantilla de andamiaje maliciosa puede eludir el mecanismo de redacción de registros para …
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
667
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.
Update
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
668
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.x antes de 4.4.1, existe potencial ejecución remota de código y robo de credenciales de cuenta debido a una vulnerabilidad de suplantación de identidad.
Update
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
669
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
Update
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59706
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
670
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.0 antes de 4.4.1, la validación indebida de los parámetros de solicitud de la API permite la ejecución remota de código.
Update
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59706
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
671
|
9.8 |
CRITICAL
Network
|
filigran
|
openaev
|
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's…
Update
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-24467
|
2026-04-26 03:00 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
672
|
8.8 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site r…
Update
|
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
|
CVE-2025-52628
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
673
|
8.8 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION está afectado por una Cookie con vulnerabilidad de SameSite insegura, impropia o ausente. Esto puede permitir que las cookies se envíen en peticiones entre sitios, aumentando potencialmente …
Update
|
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
|
CVE-2025-52628
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
674
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauth…
Update
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-52627
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
675
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
Vulnerabilidad de configuración: Sistema de archivos raíz no montado como solo lectura. Esto puede permitir modificaciones no intencionadas a archivos críticos del sistema, aumentando potencialmente …
Update
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2025-52627
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
676
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
A Potential Command Injection vulnerability in HCL AION.
An This can allow unintended command execution, potentially leading to unauthorized actions on the underlying system.This issue affects AIO…
Update
|
CWE-78
OS Command
|
CVE-2025-52626
|
2026-04-26 02:58 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
677
|
9.8 |
CRITICAL
Network
|
hcltech
|
aion
|
Una posible vulnerabilidad de inyección de comandos en HCL AION. Esto puede permitir la ejecución no intencionada de comandos, lo que podría llevar a acciones no autorizadas en el sistema subyacente.…
Update
|
CWE-78
OS Command
|
CVE-2025-52626
|
2026-04-26 02:58 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
678
|
7.5 |
HIGH
Network
|
hcltech
|
aion
|
A vulnerability
Cacheable SSL Page Found vulnerability has been identified
in HCL AION.
Cached data may expose credentials, system identifiers, or internal file paths to attackers with access t…
Update
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2025-52625
|
2026-04-26 02:58 |
2025-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
679
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processe…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-4111
|
2026-04-26 02:16 |
2026-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
680
|
7.5 |
HIGH
Network
|
-
|
-
|
Se identificó una vulnerabilidad en la lógica de descompresión de archivos RAR5 de la biblioteca libarchive, específicamente dentro de la ruta de procesamiento de archive_read_data(). Cuando se proce…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-4111
|
2026-04-26 02:16 |
2026-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
681
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-31534
|
2026-04-25 15:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
682
|
6.5 |
MEDIUM
Network
|
-
|
-
|
MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrar…
|
CWE-74
Injection
|
CVE-2026-41319
|
2026-04-25 12:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
683
|
6.7 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-4878
|
2026-04-25 11:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
684
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated us…
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-41277
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
685
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the u…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-41275
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
686
|
8.3 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Func…
|
CWE-284 CWE-918
Improper Access Control Server-Side Request Forgery (SSRF)
|
CVE-2026-41270
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
687
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorizat…
|
CWE-200 CWE-522 CWE-862
Information Exposure Insufficiently Protected Credentials Missing Authorization
|
CVE-2026-41266
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
688
|
5.9 |
MEDIUM
Network
|
-
|
-
|
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKC…
|
CWE-307 CWE-1289
mproper Restriction of Excessive Authentication Attempts Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-41213
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
689
|
7.7 |
HIGH
Network
|
-
|
-
|
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() fun…
|
CWE-129
Improper Validation of Array Index
|
CVE-2026-40886
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
690
|
7.5 |
HIGH
Network
|
p11-kit_project redhat
|
p11-kit hardened_images enterprise_linux
|
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters se…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2026-2100
|
2026-04-25 11:16 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
691
|
7.5 |
HIGH
Network
|
p11-kit_project redhat
|
p11-kit hardened_images enterprise_linux
|
Se encontró una falla en p11-kit. Un atacante remoto podría explotar esta vulnerabilidad al llamar a la función C_DeriveKey en un token remoto con parámetros específicos del mecanismo de derivación I…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2026-2100
|
2026-04-25 11:16 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
692
|
7.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a si…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-14821
|
2026-04-25 09:16 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
693
|
- |
-
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-6175
|
2026-04-25 08:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
694
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The API function `ssh_get_hexa()` is vulnerable, when 0-lenght
input is provided to this function. This function is used internally
in `ssh_get_fingerprint_hash()` and `ssh_print_hexa()` (deprecated)…
|
CWE-124
Buffer Underflow
|
CVE-2026-0966
|
2026-04-25 08:16 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
695
|
6.5 |
MEDIUM
Network
|
-
|
-
|
La función API 'ssh_get_hexa()' es vulnerable cuando se proporciona una entrada de longitud 0 a esta función. Esta función se utiliza internamente en 'ssh_get_fingerprint_hash()' y 'ssh_print_hexa()'…
|
CWE-124
Buffer Underflow
|
CVE-2026-0966
|
2026-04-25 08:16 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
696
|
3.7 |
LOW
Network
|
-
|
-
|
A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially cr…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0988
|
2026-04-25 06:16 |
2026-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
697
|
3.7 |
LOW
Network
|
-
|
-
|
Se encontró una vulnerabilidad en glib. La falta de validación de los parámetros offset y count en la función g_buffered_input_stream_peek() puede conducir a un desbordamiento de entero durante el cá…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0988
|
2026-04-25 06:16 |
2026-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
698
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
tekton_pipelines
|
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to 1.10.0, the Tekton Pipelines git resolver in API mode sends the system-configured Git API toke…
|
CWE-201 NVD-CWE-noinfo
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-40161
|
2026-04-25 05:55 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
699
|
7.5 |
HIGH
Network
|
signalk
|
signal_k_server
|
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within …
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-39320
|
2026-04-25 05:51 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
700
|
7.1 |
HIGH
Local
|
craigjbass
|
clearancekit
|
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, ClearanceKit incorrectly treats a process with an empty Team ID and a non-empty Si…
|
CWE-863
Incorrect Authorization
|
CVE-2026-40599
|
2026-04-25 05:50 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|