|
751
|
8.8 |
HIGH
Network
|
dell
|
powerprotect_dp_series_appliance data_domain_operating_system
|
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-26944
|
2026-04-23 22:59 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
5.4 |
MEDIUM
Network
|
fortra
|
goanywhere_managed_file_transfer
|
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0.
Note: The title, details, and description of this CVE were corrected post-publishing.
New
|
CWE-74
Injection
|
CVE-2026-0972
|
2026-04-23 22:47 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
7.1 |
HIGH
Network
|
openproject
|
openproject
|
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas` permission in any project can inject agenda items into meetings belonging to a…
Update
|
CWE-367 CWE-639
Time-of-check Time-of-use (TOCTOU) Race Condition Authorization Bypass Through User-Controlled Key
|
CVE-2026-40896
|
2026-04-23 22:45 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
6.5 |
MEDIUM
Network
|
fortra
|
goanywhere_managed_file_transfer
|
User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.
New
|
CWE-74
Injection
|
CVE-2026-1089
|
2026-04-23 22:45 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
7.5 |
HIGH
Network
|
internlm
|
lmdeploy
|
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language mod…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-33626
|
2026-04-23 22:39 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
7.5 |
HIGH
Network
|
junrar_project
|
junrar
|
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controll…
Update
|
CWE-22
Path Traversal
|
CVE-2026-41245
|
2026-04-23 22:35 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
7.5 |
HIGH
Network
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows unauthenticate…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35245
|
2026-04-23 22:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
7.5 |
HIGH
Local
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35246
|
2026-04-23 22:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
6.0 |
MEDIUM
Local
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privilege…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35247
|
2026-04-23 22:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
5.0 |
MEDIUM
Local
|
oracle
|
vm_virtualbox
|
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…
New
|
CWE-284
Improper Access Control
|
CVE-2026-35248
|
2026-04-23 21:59 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|