|
1411
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processe…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-4111
|
2026-04-26 02:16 |
2026-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1412
|
7.5 |
HIGH
Network
|
-
|
-
|
Se identificó una vulnerabilidad en la lógica de descompresión de archivos RAR5 de la biblioteca libarchive, específicamente dentro de la ruta de procesamiento de archive_read_data(). Cuando se proce…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-4111
|
2026-04-26 02:16 |
2026-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1413
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-31534
|
2026-04-25 15:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1414
|
6.5 |
MEDIUM
Network
|
-
|
-
|
MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrar…
|
CWE-74
Injection
|
CVE-2026-41319
|
2026-04-25 12:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1415
|
6.7 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-4878
|
2026-04-25 11:16 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1416
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated us…
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-41277
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1417
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the u…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-41275
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1418
|
8.3 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Func…
|
CWE-284 CWE-918
Improper Access Control Server-Side Request Forgery (SSRF)
|
CVE-2026-41270
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1419
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorizat…
|
CWE-200 CWE-522 CWE-862
Information Exposure Insufficiently Protected Credentials Missing Authorization
|
CVE-2026-41266
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1420
|
5.9 |
MEDIUM
Network
|
-
|
-
|
@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKC…
|
CWE-307 CWE-1289
mproper Restriction of Excessive Authentication Attempts Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-41213
|
2026-04-25 11:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|