|
1251
|
5.5 |
MEDIUM
Local
|
hkuds
|
openharness
|
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. Attac…
|
CWE-863
Incorrect Authorization
|
CVE-2026-40515
|
2026-04-25 05:34 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1252
|
6.3 |
MEDIUM
Local
|
hkuds
|
openharness
|
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP services by man…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40516
|
2026-04-25 05:32 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1253
|
7.5 |
HIGH
Network
|
firebirdsql
|
firebird
|
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher se…
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2025-65104
|
2026-04-25 05:27 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1254
|
9.8 |
CRITICAL
Network
|
samsung
|
magicinfo_9_server
|
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7399
|
2026-04-25 05:23 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1255
|
9.8 |
CRITICAL
Network
|
samsung
|
magicinfo_9_server
|
La limitación inadecuada de un nombre de ruta a una vulnerabilidad de directorio restringido en la versión Samsung MagicINFO 9 Server anterior a la 21.1050 permite a los atacantes escribir archivos a…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7399
|
2026-04-25 05:23 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1256
|
5.5 |
MEDIUM
Local
|
giskard
|
giskard
|
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to Python's re.search() wit…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-40319
|
2026-04-25 05:22 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1257
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2016 windows_server_2019 windows_server_2022
|
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
|
CWE-807
Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-0390
|
2026-04-25 05:17 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1258
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the applicati…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-41459
|
2026-04-25 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1259
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an i…
|
CWE-184
Incomplete Blacklist
|
CVE-2026-34415
|
2026-04-25 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1260
|
7.1 |
HIGH
Network
|
-
|
-
|
Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinder/php/connector.php where the name parameter in re…
|
CWE-22
Path Traversal
|
CVE-2026-34414
|
2026-04-25 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|