|
861
|
6.1 |
MEDIUM
Network
|
astro
|
astro
|
Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <sc…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41067
|
2026-04-27 22:41 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
862
|
5.4 |
MEDIUM
Adjacent
|
openprinting
|
cups
|
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP bac…
Update
|
CWE-125 CWE-200
Out-of-bounds Read Information Exposure
|
CVE-2026-41079
|
2026-04-27 22:40 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
863
|
6.6 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file …
Update
|
CWE-78
OS Command
|
CVE-2026-41411
|
2026-04-27 22:39 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
864
|
9.8 |
CRITICAL
Network
|
oracle
|
advanced_inbound_telephony
|
Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily explo…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-34275
|
2026-04-27 22:09 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
865
|
6.5 |
MEDIUM
Network
|
oracle
|
peoplesoft_enterprise_fin_contracts
|
Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Contracts). The supported version that is affected is 9.2. Easily exploitable vulnerability allows …
Update
|
CWE-200
Information Exposure
|
CVE-2026-34300
|
2026-04-27 22:08 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
866
|
2.4 |
LOW
Network
|
oracle
|
database_server
|
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Acces…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-34312
|
2026-04-27 22:04 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
867
|
5.4 |
MEDIUM
Network
|
oracle
|
fusion_middleware
|
Vulnerability in Oracle Fusion Middleware (component: Dynamic Monitoring Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low pr…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-35232
|
2026-04-27 22:03 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
868
|
6.4 |
MEDIUM
Network
|
oracle
|
fusion_middleware
|
Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Supported versions that are affected are 12.2.1.4.0 and 12.1.3.0.0. Difficult to expl…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-35252
|
2026-04-27 22:02 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
869
|
7.3 |
HIGH
Local
|
uutils
|
coreutils
|
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not …
Update
|
CWE-22
Path Traversal
|
CVE-2026-35338
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
870
|
3.3 |
LOW
Local
|
uutils
|
coreutils
|
The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid UTF-8 b…
Update
|
CWE-176
Improper Handling of Unicode Encoding
|
CVE-2026-35346
|
2026-04-27 21:28 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|