|
741
|
7.8 |
HIGH
Local
|
parzivalhack
|
pyspector
|
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis to preve…
Update
|
CWE-184
Incomplete Blacklist
|
CVE-2026-41206
|
2026-04-30 00:48 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
742
|
5.4 |
MEDIUM
Network
|
siemvk
|
openlearn
|
OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but …
Update
|
CWE-284
Improper Access Control
|
CVE-2026-41243
|
2026-04-30 00:39 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
743
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
can: raw: fix ro->uniq use-after-free in raw_rcv()
raw_release() unregisters raw CAN receive filters via can_rx_unregister(),
but…
Update
|
CWE-416
Use After Free
|
CVE-2026-31532
|
2026-04-30 00:26 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
744
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566e9c0d15a16414c. This impacts the function search_papers of the file research_se…
New
|
CWE-22
Path Traversal
|
CVE-2026-7384
|
2026-04-30 00:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
745
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Symlink Attack.
This issue affects Pardus …
New
|
CWE-59
Link Following
|
CVE-2026-5161
|
2026-04-30 00:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
746
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus allows Authentication Bypass.
This issue affects Pardus: …
New
|
CWE-93
CRLF Injection
|
CVE-2026-5140
|
2026-04-30 00:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
747
|
- |
|
-
|
-
|
TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.
New
|
-
|
CVE-2026-36841
|
2026-04-30 00:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
748
|
9.8 |
CRITICAL
Network
|
pipecat
|
pipecat
|
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an opti…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-62373
|
2026-04-30 00:00 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
749
|
6.1 |
MEDIUM
Network
|
cure53
|
dompurify
|
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TA…
|
CWE-79 CWE-183
Cross-site Scripting Permissive List of Allowed Inputs
|
CVE-2026-41240
|
2026-04-29 23:58 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
750
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption
The -EBUSY handling in tls_do_encryption(), introduced by c…
|
CWE-416
Use After Free
|
CVE-2026-31533
|
2026-04-29 23:51 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|