|
1291
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
s390/entry: Scrub r12 register on kernel entry
Before commit f33f2d4c7c80 ("s390/bp: remove TIF_ISOLATE_BP"),
all entry handlers …
|
NVD-CWE-noinfo
|
CVE-2026-31482
|
2026-04-28 22:46 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1292
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
s390/syscalls: Add spectre boundary for syscall dispatch table
The s390 syscall number is directly controlled by userspace, but d…
|
NVD-CWE-noinfo
|
CVE-2026-31483
|
2026-04-28 22:40 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1293
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
io_uring/fdinfo: fix OOB read in SQE_MIXED wrap check
__io_uring_show_fdinfo() iterates over pending SQEs and, for 128-byte
SQEs …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31484
|
2026-04-28 22:39 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1294
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-bu…
|
CWE-426
Untrusted Search Path
|
CVE-2026-7309
|
2026-04-28 22:19 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1295
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an unknown function of the file server/sdk-server.ts of the component creative-ad-ag…
|
CWE-22
Path Traversal
|
CVE-2026-7271
|
2026-04-28 22:19 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1296
|
- |
|
-
|
-
|
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user accounts, enumerate…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-6043
|
2026-04-28 22:19 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1297
|
- |
|
-
|
-
|
An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their …
|
CWE-285
Improper Authorization
|
CVE-2026-5781
|
2026-04-28 22:19 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1298
|
- |
|
-
|
-
|
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authentic…
|
CWE-284
Improper Access Control
|
CVE-2026-5780
|
2026-04-28 22:19 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1299
|
- |
|
-
|
-
|
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the inf…
|
CWE-284
Improper Access Control
|
CVE-2026-5779
|
2026-04-28 22:19 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1300
|
8.8 |
HIGH
Network
|
-
|
-
|
The ConsulRegistry in the camel-consul component (class org.apache.camel.component.consul.ConsulRegistry and its inner ConsulRegistryUtils.deserialize method) read Java-serialized values from the Con…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-27172
|
2026-04-28 22:18 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|