|
491
|
8.8 |
HIGH
Network
|
goshs
|
goshs
|
goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global ba…
Update
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-40885
|
2026-04-27 23:51 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
492
|
8.7 |
HIGH
Local
|
linaro
|
op-tee
|
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, mi…
Update
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2026-33317
|
2026-04-27 23:50 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
493
|
6.5 |
MEDIUM
Network
|
apache
|
activemq activemq_web
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsin…
Update
|
CWE-79 CWE-915
Cross-site Scripting Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-41043
|
2026-04-27 23:49 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
494
|
8.8 |
HIGH
Network
|
apache
|
activemq activemq_broker
|
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All.
An authenticated attacker can use …
Update
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2026-41044
|
2026-04-27 23:49 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
495
|
9.8 |
CRITICAL
Network
|
ericsson
|
codechecker
|
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
Authentication bypass occurs when the URL ends with Authentication with certain…
Update
|
CWE-290 CWE-863
Authentication Bypass by Spoofing Incorrect Authorization
|
CVE-2026-25660
|
2026-04-27 23:48 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
496
|
8.8 |
HIGH
Network
|
mathjs
|
mathjs
|
Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be a…
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-40897
|
2026-04-27 23:47 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
497
|
4.3 |
MEDIUM
Network
|
xibosignage
|
xibo
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL t…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-31956
|
2026-04-27 23:44 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
498
|
4.9 |
MEDIUM
Network
|
xibosignage
|
xibo
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-31955
|
2026-04-27 23:43 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
499
|
5.4 |
MEDIUM
Network
|
xibosignage
|
xibo
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.4.1 …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-31953
|
2026-04-27 23:43 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
500
|
3.3 |
LOW
Local
|
chainguard
|
melange
|
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also usable via `me…
Update
|
CWE-22
Path Traversal
|
CVE-2026-29051
|
2026-04-27 23:42 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|