Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

CVE güvenlik açıkları, KEV etiketleri, detay sayfaları ve kategori bazlı listeleme.
Toplam kayıt70,096
Sayfa1 / 3505
FiltreYok
Low CVSS: 2.7 Yayın: 2026-04-22 03:16:01

CVE-2026-6416

Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
Low CVSS: 2.7 Yayın: 2026-04-22 03:16:01

CVE-2026-6408

Tanium addressed an information disclosure vulnerability in Tanium Server.
Low CVSS: 2.7 Yayın: 2026-04-22 03:16:01

CVE-2026-6392

Tanium addressed an information disclosure vulnerability in Threat Response.
Unknown CVSS: - Yayın: 2026-04-22 03:16:01

CVE-2026-6386

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the sh…
Unknown CVSS: - Yayın: 2026-04-22 03:16:01

CVE-2026-5398

The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to fr…
High CVSS: 8.2 Yayın: 2026-04-22 03:16:01

CVE-2026-41458

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can fl…
Medium CVSS: 6.9 Yayın: 2026-04-22 03:16:00

CVE-2026-41457

OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= parameters for in…
High CVSS: 8.7 Yayın: 2026-04-22 02:16:02

CVE-2026-41146

facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value starting with `i` or `I`. The process spins in user spa…
High CVSS: 8.8 Yayın: 2026-04-22 01:16:05

CVE-2026-41145

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path allows any user wh…
High CVSS: 8.8 Yayın: 2026-04-22 01:16:05

CVE-2026-40344

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows…
High CVSS: 8.9 Yayın: 2026-04-22 00:16:29

CVE-2026-41304

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is di…
Unknown CVSS: - Yayın: 2026-04-22 00:16:29

CVE-2026-41144

F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An…
Medium CVSS: 5.5 Yayın: 2026-04-22 00:16:29

CVE-2026-41136

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` d…
High CVSS: 7.5 Yayın: 2026-04-22 00:16:29

CVE-2026-41135

free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability in versions prior to 1.4.3 allows any unauthenticated attacker with network access to th…
High CVSS: 8.8 Yayın: 2026-04-22 00:16:29

CVE-2026-41133

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin c…
Medium CVSS: 5.0 Yayın: 2026-04-22 00:16:29

CVE-2026-41131

OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could resul…
Medium CVSS: 5.5 Yayın: 2026-04-22 00:16:28

CVE-2026-41130

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trust…
Medium CVSS: 5.5 Yayın: 2026-04-22 00:16:28

CVE-2026-41129

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL s…
Medium CVSS: 5.3 Yayın: 2026-04-22 00:16:28

CVE-2026-41128

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces…
Medium CVSS: 6.5 Yayın: 2026-04-22 00:16:28

CVE-2026-41127

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds…