|
331
|
- |
|
-
|
-
|
STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scrip…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41200
|
2026-04-30 05:46 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Limit PTP to a single page
Commit 391e69143d0a increased CT_PTP_NUM from 1 to 4 to support 256
playback streams, but…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31602
|
2026-04-30 05:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
9.8 |
CRITICAL
Network
|
-
|
-
|
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metachara…
Update
|
CWE-78
OS Command
|
CVE-2026-6942
|
2026-04-30 05:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
8.5 |
HIGH
Network
|
socialengine
|
socialengine
|
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is no…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41461
|
2026-04-30 05:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
9.8 |
CRITICAL
Network
|
socialengine
|
socialengine
|
SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized befo…
Update
|
CWE-89
SQL Injection
|
CVE-2026-41460
|
2026-04-30 05:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
6.2 |
MEDIUM
Local
|
apple
|
ipados iphone_os
|
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly …
Update
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-28950
|
2026-04-30 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
5.1 |
MEDIUM
Local
|
-
|
-
|
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in thi…
Update
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-10549
|
2026-04-30 05:16 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime upda…
New
|
CWE-295 CWE-296 CWE-494
Improper Certificate Validation Improper Following of a Certificate's Chain of Trust Download of Code Without Integrity Check
|
CVE-2025-10539
|
2026-04-30 05:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vfio/xe: Reorganize the init to decouple migration from reset
Attempting to issue reset on VF devices that don't support migratio…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31601
|
2026-04-30 05:15 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
arm64: mm: Handle invalid large leaf mappings correctly
It has been possible for a long time to mark ptes in the linear map as
in…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31600
|
2026-04-30 05:14 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|