|
941
|
5.3 |
MEDIUM
Network
|
oracle
|
goldengate
|
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerability allows unauthenticated attacker with network access v…
Update
|
CWE-200
Information Exposure
|
CVE-2026-34273
|
2026-04-28 03:08 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
7.5 |
HIGH
Network
|
oracle
|
financial_services_customer_screening
|
Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.1.2.8.0.…
Update
|
CWE-285
Improper Authorization
|
CVE-2026-34320
|
2026-04-28 03:08 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
7.5 |
HIGH
Network
|
oracle
|
financial_services_transaction_filtering
|
Vulnerability in the Oracle Financial Services Transaction Filtering product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.1.2.8…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-35231
|
2026-04-28 03:07 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
5.4 |
MEDIUM
Network
|
linuxfoundation
|
tekton_pipelines
|
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restr…
Update
|
CWE-22
Path Traversal
|
CVE-2026-40923
|
2026-04-28 03:07 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
tekton_pipelines
|
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40924
|
2026-04-28 03:06 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
7.5 |
HIGH
Network
|
lxml
|
lxml
|
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML in…
Update
|
CWE-611
XXE
|
CVE-2026-41066
|
2026-04-28 02:59 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
7.7 |
HIGH
Network
|
kyverno
|
kyverno
|
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user wit…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-41485
|
2026-04-28 02:54 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
9.1 |
CRITICAL
Network
|
kyverno
|
kyverno
|
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically attache…
Update
|
CWE-200 CWE-918
Information Exposure Server-Side Request Forgery (SSRF)
|
CVE-2026-41323
|
2026-04-28 02:53 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
7.5 |
HIGH
Network
|
patrickjuchli
|
basic-ftp
|
basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A mal…
Update
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-41324
|
2026-04-28 02:48 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
7.7 |
HIGH
Network
|
kyverno
|
kyverno
|
Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating t…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41068
|
2026-04-28 02:48 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|