|
381
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowi…
New
|
CWE-436 CWE-863
Interpretation Conflict Incorrect Authorization
|
CVE-2026-41248
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
382
|
7.8 |
HIGH
Local
|
-
|
-
|
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTe…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-42171
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
383
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) t…
New
|
CWE-94
Code Injection
|
CVE-2026-6951
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
384
|
7.4 |
HIGH
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attac…
Update
|
CWE-113 CWE-1321
HTTP Response Splitting Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-42035
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
385
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into th…
Update
|
CWE-93
CRLF Injection
|
CVE-2026-42037
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
386
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype…
Update
|
CWE-287 CWE-1321
Improper Authentication Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-42041
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
387
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype…
Update
|
CWE-915 CWE-1321
Improperly Controlled Modification of Dynamically-Determined Object Attributes Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-42044
|
2026-04-28 03:57 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
388
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation…
New
|
CWE-404 CWE-835
Improper Resource Shutdown or Release Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-6985
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
389
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation result…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-6987
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
390
|
8.8 |
HIGH
Network
|
-
|
-
|
A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon. This issue affects the function formRoute of the file /boaform/formRouting of the component Boa Service. This manipulation of the…
New
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-6988
|
2026-04-28 03:57 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|