|
771
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict …
Update
|
CWE-183 CWE-201
Permissive List of Allowed Inputs Insertion of Sensitive Information Into Sent Data
|
CVE-2026-42042
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
772
|
7.2 |
HIGH
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 r…
Update
|
CWE-183 CWE-441 CWE-918
Permissive List of Allowed Inputs Confused Deputy Server-Side Request Forgery (SSRF)
|
CVE-2026-42043
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
773
|
- |
|
-
|
-
|
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFil…
Update
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-41326
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
774
|
7.4 |
HIGH
Network
|
-
|
-
|
Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with …
Update
|
CWE-94
Code Injection
|
CVE-2026-41414
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
775
|
7.4 |
HIGH
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attac…
Update
|
CWE-113 CWE-1321
HTTP Response Splitting Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-42035
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
776
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into th…
Update
|
CWE-93
CRLF Injection
|
CVE-2026-42037
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
777
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype…
Update
|
CWE-287 CWE-1321
Improper Authentication Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-42041
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
778
|
5.3 |
MEDIUM
Network
|
-
|
-
|
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). …
Update
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-41418
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
779
|
7.6 |
HIGH
Network
|
-
|
-
|
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbit…
Update
|
CWE-22
Path Traversal
|
CVE-2026-41419
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
780
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype…
Update
|
CWE-915 CWE-1321
Improperly Controlled Modification of Dynamically-Determined Object Attributes Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-42044
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|