Low
CVSS: 2.7
Yayın: 2026-04-22 03:16:01
Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
Low
CVSS: 2.7
Yayın: 2026-04-22 03:16:01
Tanium addressed an information disclosure vulnerability in Tanium Server.
Low
CVSS: 2.7
Yayın: 2026-04-22 03:16:01
Tanium addressed an information disclosure vulnerability in Threat Response.
Unknown
CVSS: -
Yayın: 2026-04-22 03:16:01
In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage mappings created using the sh…
Unknown
CVSS: -
Yayın: 2026-04-22 03:16:01
The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to fr…
High
CVSS: 8.2
Yayın: 2026-04-22 03:16:01
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can fl…
Medium
CVSS: 6.9
Yayın: 2026-04-22 03:16:00
OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= parameters for in…
High
CVSS: 8.7
Yayın: 2026-04-22 02:16:02
facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinite loop when it encounters a nested JSON value starting with `i` or `I`. The process spins in user spa…
High
CVSS: 8.8
Yayın: 2026-04-22 01:16:05
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path
allows any user wh…
High
CVSS: 8.8
Yayın: 2026-04-22 01:16:05
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows…
High
CVSS: 8.9
Yayın: 2026-04-22 00:16:29
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is di…
Unknown
CVSS: -
Yayın: 2026-04-22 00:16:29
F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An…
Medium
CVSS: 5.5
Yayın: 2026-04-22 00:16:29
free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` d…
High
CVSS: 7.5
Yayın: 2026-04-22 00:16:29
free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability in versions prior to 1.4.3 allows any unauthenticated attacker with network access to th…
High
CVSS: 8.8
Yayın: 2026-04-22 00:16:29
pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin c…
Medium
CVSS: 5.0
Yayın: 2026-04-22 00:16:29
OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could resul…
Medium
CVSS: 5.5
Yayın: 2026-04-22 00:16:28
Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources.
When `trust…
Medium
CVSS: 5.5
Yayın: 2026-04-22 00:16:28
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL s…
Medium
CVSS: 5.3
Yayın: 2026-04-22 00:16:28
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces…
Medium
CVSS: 6.5
Yayın: 2026-04-22 00:16:28
BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds…