|
451
|
7.8 |
HIGH
Local
|
-
|
-
|
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not pro…
New
|
CWE-416
Use After Free
|
CVE-2026-5943
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
452
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCountrystr. The manipulation of the argument countrystr results in os command injec…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7119
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
453
|
- |
|
-
|
-
|
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-15626
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
454
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table exhaustion.
Plug.Cowboy.Conn.conn/1 in li…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-32688
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
455
|
- |
|
-
|
-
|
Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter
Versions Affected: from 2.6.3 to 2.8.6
Description:
In production deployments where an admin…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40557
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
456
|
- |
|
-
|
-
|
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1
New
|
CWE-278
Insecure Preserved Inherited Permissions
|
CVE-2026-6265
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
457
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm
Versions Affected: up to 2.8.7
Description: When TLS transport is enabled in Apache …
New
|
CWE-287
Improper Authentication
|
CVE-2026-41081
|
2026-04-28 03:57 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
458
|
- |
|
-
|
-
|
An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
New
|
-
|
CVE-2026-30350
|
2026-04-28 03:57 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
459
|
5.9 |
MEDIUM
Network
|
-
|
-
|
SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from Sy…
New
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2026-40514
|
2026-04-28 03:57 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
460
|
- |
|
-
|
-
|
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally defe…
New
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-6357
|
2026-04-28 03:57 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|