Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Vulnerability List - Page 53

CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-41170 Squidex has SSRF via Backup Restore Endpoint — Admin-Controlled URL Download Allows Internal and External Requests Squidexsquidex--2026-04-22 21:13:19 Deep Dive
CVE-2026-41455 WeKan < 8.35 SSRF via Webhook URL wekanwekan High 8.5 2026-04-22 21:09:30 Deep Dive
CVE-2026-41454 WeKan < 8.35 Missing Authorization via Integration REST API wekanwekan High 8.3 2026-04-22 21:08:39 Deep Dive
CVE-2026-41314 pypdf: Manipulated FlateDecode image dimensions can exhaust RAM py-pdfpypdf--2026-04-22 21:08:15 Deep Dive
CVE-2026-41313 pypdf: Possible long runtimes for wrong size values in incremental mode py-pdfpypdf--2026-04-22 21:05:00 Deep Dive
CVE-2026-41312 pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM py-pdfpypdf--2026-04-22 21:02:53 Deep Dive
CVE-2026-41168 pypdf has possible long runtimes for wrong size values in cross-reference and object streams py-pdfpypdf--2026-04-22 20:49:10 Deep Dive
CVE-2026-41167 Jellystat has SQL Injection that leads to to Remote Code Execution CyferShepardJellystat Critical 9.1 2026-04-22 20:39:31 Deep Dive
CVE-2026-40882 OpenRemote has XXE in Velbus Asset Import openremoteopenremote High 7.6 2026-04-22 20:33:23 Deep Dive
CVE-2026-41166 OpenRemote has Improper Access Control via updateUserRealmRoles function openremoteopenremote High 7.0 2026-04-22 20:31:29 Deep Dive
CVE-2026-41134 Kiota: Code Generation Literal Injection microsoftkiota--2026-04-22 20:20:58 Deep Dive
CVE-2026-40937 RustFS missing admin authorization on notification target endpoints, which allows unauthenticated configuration of event webhooks rustfsrustfs High 8.3 2026-04-22 20:15:57 Deep Dive
CVE-2026-33733 EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete espocrmespocrm High 7.2 2026-04-22 20:05:24 Deep Dive
CVE-2026-33656 EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user espocrmespocrm Critical 9.1 2026-04-22 20:01:24 Deep Dive
CVE-2026-34068 nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge nimiqnimiq-transaction Medium 6.8 2026-04-22 19:55:08 Deep Dive
CVE-2026-3837 Frappe Framework 16.10.0 - Stored DOM XSS in Multiple Field Formatters FrappeFrappe--2026-04-22 19:52:56 Deep Dive
CVE-2026-34067 nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch nimiqnimiq-transaction Low 3.1 2026-04-22 19:52:44 Deep Dive
CVE-2026-34066 nimiq-blockchain: Peer-triggerable panic during history sync nimiqnimiq-blockchain Medium 5.3 2026-04-22 19:47:49 Deep Dive
CVE-2026-34065 nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals nimiqnimiq-primitives High 7.5 2026-04-22 19:45:01 Deep Dive
CVE-2026-34064 nimiq-account: Vesting insufficient funds error can panic nimiqnimiq-account Medium 5.3 2026-04-22 19:43:04 Deep Dive