CVE-2026-2708
— Libsoup: libsoup: http request smuggling via duplicate content-length headers
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each hea…
Remote
|
Misconfiguration
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-32172
— Microsoft Power Apps Remote Code Execution Vulnerability
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-35431
— Microsoft Entra ID Entitlement Management Spoofing Vulnerability
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-24303
— Microsoft Partner Center Elevation of Privilege Vulnerability
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-26150
— Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-33102
— Microsoft 365 Copilot Elevation of Privilege Vulnerability
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-32210
— Microsoft Dynamics 365 (online) Spoofing Vulnerability
None
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-26210
— KTransformers Unsafe Deserialization RCE via balance_serve
KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authe…
Remote
|
Misconfiguration
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-6942
— radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass
radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metachara…
Remote
|
Injection
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-6941
— radare2 < 6.1.4 Project Notes Path Traversal via Symlink
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the configured project directory by importing a malic…
|
Path Traversal
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-6940
— radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the …
|
Path Traversal
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-6376
— Missing authentication for critical function in SpiceJet Online Booking System
A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only a PNR and last name, with no authentication or verification mechanisms. This re…
Remote
|
Authentication
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-6375
— Authorization bypass through User-Controlled key in SpiceJet Online Booking System
A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an att…
Remote
|
Authorization
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-28525
— SWUpdate Integer Underflow in Multipart Upload Parser
SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to cause a denial of service by sending a crafted HTT…
Remote
|
Denial of Service
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execut…
|
Injection
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-41279
— Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API cred…
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (…
Remote
|
Authentication
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-41278
— Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API ke…
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitiz…
Remote
|
Information Disclosure
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-41277
— Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object…
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated us…
Remote
|
Authorization
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
CVE-2026-41276
— Flowise: AccountService resetPassword Authentication Bypass Vulnerability
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations …
Remote
|
Authentication
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Apr 23, 2026