CVE Feed

    Dashboard / CVE

    4.1
    Medium

    CVE-2026-40566

    Last Modified: 22 Apr 2026

    FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX actions `fetch_test` (line 731), `send_test` (line 682), and `imap_folders` (line 773) in `app/Http/Controllers/MailboxesController.php` pass admin-configured `in_server`/`in_port` and `out_server`/`out_port` values directly to `fsockopen()` via `Helper::checkPort()` and to IMAP/SMTP client connections with zero SSRF protection. There is no IP validation, no hostname restriction, no blocklist of internal ranges, and no call to the project's own `sanitizeRemoteUrl()` or `checkUrlIpAndHost()` functions. The validation block in `connectionIncomingSave()` is entirely commented out. An authenticated admin can configure a mailbox's IMAP or SMTP server to point at any internal host and port, then trigger a connection test. The server opens raw TCP connections (via `fsockopen()`) and protocol-level connections (via IMAP client or SMTP transport) to the attacker-specified target. The response differentiates open from closed ports, enabling internal network port scanning. When the IMAP client connects to a non-IMAP service, the target's service banner or error response is captured in the IMAP debug log and returned in the AJAX response's `log` field, making this a semi-blind SSRF that enables service fingerprinting. In cloud environments, the metadata endpoint at `169[.]254[.]169[.]254` can be probed and partial response data may be leaked through protocol error messages. This is distinct from the `sanitizeRemoteUrl()` redirect bypass (freescout-3) -- different code path, different root cause, different protocol layer. Version 1.8.213 patches the vulnerability.

    Published: 21 Apr 2026
    6.1
    Medium

    CVE-2026-40565

    Last Modified: 22 Apr 2026

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getCleanBody()) preserves literal " characters in text nodes. linkify() then wraps URLs including those " chars inside an unescaped href="..." attribute, breaking out of the href and injecting arbitrary HTML attributes. Version 1.8.213 fixes the issue.

    Published: 21 Apr 2026
    10
    Critical

    CVE-2025-15638

    Last Modified: 22 Apr 2026

    Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.

    Published: 21 Apr 2026
    10
    Critical

    CVE-2017-20230

    Last Modified: 22 Apr 2026

    Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer but in read operations treated the length as unsigned. This allowed an attacker to craft data that could trigger the overflow.

    Published: 21 Apr 2026
    5.1
    Medium

    CVE-2025-41011

    Last Modified: 6 May 2026

    HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.

    Published: 21 Apr 2026
    8.9
    High

    CVE-2026-40498

    Last Modified: 22 Apr 2026

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system tools that should be restricted to administrators. The /system/cron endpoint relies on a static MD5 hash derived from the APP_KEY, which is exposed in the response and logs. Accessing these endpoints reveals sensitive server information (Full Path Disclosure), process IDs, and allows for Resource Exhaustion (DoS) by triggering heavy background tasks repeatedly without any rate limiting. The cron hash is generated using md5(APP_KEY . 'web_cron_hash'). Since this hash is often transmitted via GET requests, it is susceptible to exposure in server logs, browser history, and proxy logs. Furthermore, the lack of rate limiting on these endpoints allows for automated resource exhaustion (DoS) and brute-force attempts. Version 1.8.213 fixes the issue.

    Published: 21 Apr 2026
    9.3
    Critical

    CVE-2025-41029

    Last Modified: 22 Apr 2026

    SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameter 'phonenumber' in '/private/continue-upload.php'.

    Published: 21 Apr 2026
    8.8
    High

    CVE-2026-3298

    Last Modified: 10 Aug 2026

    The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

    Published: 21 Apr 2026
    5.1
    Medium

    CVE-2025-10354

    Last Modified: 21 Apr 2026

    Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the '/index.php/Speciaal:GefacetteerdZoeken' endpoint parameter. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2025-31981

    Last Modified: 22 Apr 2026

    HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

    Published: 21 Apr 2026
    8.5
    High

    CVE-2026-5789

    Last Modified: 22 Apr 2026

    Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration.

    Published: 21 Apr 2026
    6.5
    Medium

    CVE-2026-1089

    Last Modified: 23 Apr 2026

    User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.

    Published: 21 Apr 2026
    5.4
    Medium

    CVE-2026-0972

    Last Modified: 29 Apr 2026

    HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

    Published: 21 Apr 2026
    4.3
    Medium

    CVE-2026-0971

    Last Modified: 23 Apr 2026

    An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.

    Published: 21 Apr 2026
    7.3
    High

    CVE-2025-14362

    Last Modified: 23 Apr 2026

    The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

    Published: 21 Apr 2026
    5.8
    Medium

    CVE-2025-1241

    Last Modified: 23 Apr 2026

    Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.

    Published: 21 Apr 2026
    3.7
    Low

    CVE-2025-31958

    Last Modified: 22 Apr 2026

    HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6786

    Last Modified: 28 Apr 2026

    Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6784

    Last Modified: 7 May 2026

    Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6785

    Last Modified: 27 May 2026

    Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6783

    Last Modified: 27 May 2026

    Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6781

    Last Modified: 22 Apr 2026

    Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6782

    Last Modified: 22 Apr 2026

    Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6780

    Last Modified: 22 Apr 2026

    Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6779

    Last Modified: 22 Apr 2026

    Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6778

    Last Modified: 27 May 2026

    Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6777

    Last Modified: 22 Apr 2026

    Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.8
    High

    CVE-2026-6776

    Last Modified: 22 Apr 2026

    Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6775

    Last Modified: 22 Apr 2026

    Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    8.6
    High

    CVE-2026-40520

    Last Modified: 23 Apr 2026

    FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations mutation with backtick-wrapped commands in the module field to execute arbitrary commands on the underlying host as the web server user.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6773

    Last Modified: 22 Apr 2026

    Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    5.4
    Medium

    CVE-2026-6774

    Last Modified: 22 Apr 2026

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6772

    Last Modified: 22 Apr 2026

    Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    9.8
    Critical

    CVE-2026-6771

    Last Modified: 22 Apr 2026

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    6.5
    Medium

    CVE-2026-6770

    Last Modified: 22 Apr 2026

    Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    8.8
    High

    CVE-2026-6769

    Last Modified: 23 Apr 2026

    Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    9.8
    Critical

    CVE-2026-6768

    Last Modified: 22 Apr 2026

    Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6767

    Last Modified: 22 Apr 2026

    Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6766

    Last Modified: 22 Apr 2026

    Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    6.5
    Medium

    CVE-2026-6764

    Last Modified: 22 Apr 2026

    Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    5.3
    Medium

    CVE-2026-6765

    Last Modified: 27 May 2026

    Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    6.5
    Medium

    CVE-2026-6763

    Last Modified: 22 Apr 2026

    Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    8.8
    High

    CVE-2026-6761

    Last Modified: 23 Apr 2026

    Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    6.3
    Medium

    CVE-2026-6762

    Last Modified: 27 Apr 2026

    Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    9.8
    Critical

    CVE-2026-6760

    Last Modified: 27 Apr 2026

    Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6759

    Last Modified: 22 Apr 2026

    Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6758

    Last Modified: 22 Apr 2026

    Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026
    6.3
    Medium

    CVE-2026-6757

    Last Modified: 22 Apr 2026

    Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

    Published: 21 Apr 2026
    7.5
    High

    CVE-2026-6756

    Last Modified: 22 Apr 2026

    Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.

    Published: 21 Apr 2026
    6.5
    Medium

    CVE-2026-6755

    Last Modified: 22 Apr 2026

    Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

    Published: 21 Apr 2026