CVE-2026-40353 - wger: Stored XSS via Unescaped License Attribution Fields
Autor Apr 18, 2026 0 0
CVE-2026-23500 - Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
Autor Apr 18, 2026 0 0
CVE-2026-33689 - xrdp: Pre-authentication out-of-bounds reads in channel parsers
Autor Apr 18, 2026 0 0
CVE-2026-33436 - Stirling-PDF: Reflected XSS through crafted filename in file upload functionality
Autor Apr 18, 2026 0 0
CVE-2026-33145 - xrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesman
Autor Apr 18, 2026 0 0
CVE-2026-40196 - HomeBox has Unauthorized API Access via Retained defaultGroup ID After Group Access Revocation
Autor Apr 18, 2026 0 0
CVE-2026-40155 - Auth0 Next.js SDK has Improper Proxy Cache Lookup
Autor Apr 18, 2026 0 0
CVE-2026-35603 - Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
Autor Apr 18, 2026 0 0
CVE-2026-35512 - xrdp: Heap buffer overflow in EGFX channel
Autor Apr 18, 2026 0 0
CVE-2026-35402 - mcp-neo4j-cypher: SSRF and Data Modification via read_only Mode Bypass Through CALL Procedures
Autor Apr 18, 2026 0 0
CVE-2026-40285 - WeGIA has SQL Injection via Session Variable Override in DespachoControle.php
Autor Apr 18, 2026 0 0
CVE-2026-40282 - WeGIA has stored XSS in intercorrencia_visualizar.php
Autor Apr 18, 2026 0 0
CVE-2026-40302 - zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
Autor Apr 18, 2026 0 0

