Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 14 April 2026

RSS

761 vulnerabilities published on 14 April 2026

Severity:
WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
GHSA-j432-4w3j-3w8j
## Summary The `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` to bypass all SS...
7.7
goshs Exposes Folder Credentials on Public Collaborator Feed
GHSA-7h3j-592v-jcrp
When goshs is deployed without a global username and password, an attacker can intercept a user's folder credentials through the public collaborator feed and use them to access and modify files in the...
7.7
ColdFusion: Unauthorized Access to Files Through Path Traversal
CVE-2026-34619
ColdFusion versions 2023.18 and earlier have a security flaw that allows an attacker to access files they shouldn't be able to. This could happen without the user knowing, and it's a serious issue tha...
7.7
OpenStack Keystone Users Can Authenticate Even When Disabled in LDAP
CVE-2026-40683
OpenStack Keystone versions before 28.0.1 have a bug that allows users who are disabled in LDAP to still log in and access resources. This is a security concern for organizations using Keystone's LDAP...
7.7
Kyverno Allows Unauthorized Access to Internal Resources
GHSA-fmqp-4wfc-w3v7
Kyverno's APICall feature in multi-tenant Kubernetes environments can be exploited by low-privilege users to access sensitive data from other tenants, such as database passwords and API keys, without ...
7.7
Kyverno Policy Allows Unrestricted Access to Internal Resources
GHSA-fmqp-4wfc-w3v7
A vulnerability in Kyverno's APICall feature allows users with Policy creation permissions to access sensitive data from other tenants, breaking multi-tenant isolation. This means a malicious user cou...
7.7
Kyverno API Calls Can Be Tricked into Accessing Unauthorized Endpoints
GHSA-qr4g-8hrp-c4rw
Kyverno's API call feature can be exploited by authenticated users to make requests to any website or service, potentially revealing internal network information. This could happen if an attacker can ...
7.7
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
GHSA-qr4g-8hrp-c4rw
### Summary A Server-Side Request Forgery (SSRF) vulnerability in Kyverno allows authenticated users to induce the admission controller to send arbitrary HTTP requests to attacker-controlled endpoints...
7.7
Windows BitLocker Input Validation Weakness Allows Local Bypass
CVE-2026-27913
An attacker with physical access to a Windows system can potentially bypass BitLocker encryption by exploiting a weakness in input validation. This means they may be able to access encrypted data with...
7.7
Deno: Untrusted Input Can Bypass Permission Prompt
JLSEC-2026-106
Deno's permission prompts can be manipulated by an attacker using special terminal sequences. This allows an attacker to bypass Deno's security settings and potentially perform actions that the user d...
7.7
pyLoad: User Can Access Data After Permission Changes
GHSA-fj52-5g4h-gmq8
If an administrator changes a user's permissions, the user's session may still allow them to access data they shouldn't. This means a user who loses access to certain features can still use a valid se...
7.6
Denial of Service in .NET
CVE-2026-26171 GHSA-w3x6-4m5h-cxqf
An attacker can use a malicious request to consume excessive system resources, potentially causing .NET applications to become unresponsive or crash. This can impact the availability of affected syste...
7.5
Uncontrolled Loop in .NET, .NET Framework, Visual Studio Denies Network Access
CVE-2026-33116 GHSA-37gx-xxp4-5rgx
.NET, .NET Framework, and Visual Studio have a bug that can cause a computer to freeze or crash when processing certain network requests. This could prevent others from using the computer or network. ...
7.5
Microsoft .NET Spoofing Vulnerability in Network Communications
CVE-2026-32178 GHSA-vmwf-m9c5-3jvc
An attacker can use this vulnerability to trick a .NET application into thinking it's communicating with a trusted source, allowing unauthorized access to sensitive information. This affects .NET appl...
7.5
Go Markdown can crash when processing certain text inputs
GHSA-77fj-vx54-gvh7
A specific type of text input can cause the Go Markdown library to crash or behave unexpectedly. This can affect websites and applications that use Go Markdown to render text. To protect against this,...
7.5
Decidim's comments API allows access to all commentable resources
GHSA-ghmh-q25g-gxxx
### Impact The root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission checks. All Decidim instances are impacted that have not...
7.5
Decidim: Anyone can accept or reject amendments
GHSA-w5xj-99cg-rccm
Any registered user can accept or reject amendments on proposals, giving them authorship, which could be a concern for proposal creators. This is a risk for anyone using Decidim's amendment feature. T...
7.5
Decidim: Anyone can accept or reject proposals
GHSA-w5xj-99cg-rccm
A security issue allows any registered user to accept or reject changes to proposals, potentially affecting the ownership and co-authorship of those proposals. This issue affects versions 0.19.0 and l...
7.5
ColdFusion versions 2023.18 and earlier: Attackers could bypass security features
CVE-2026-27282
Certain versions of ColdFusion are vulnerable to an input validation issue. An attacker could trick a user into doing something that lets them access the system without permission. To protect your sys...
7.5
Justhtml 1.16.0 fixes security risks in HTML sanitization
GHSA-4p64-v8f5-r2gx
Justhtml versions 1.15.0 and earlier have security weaknesses in how they handle certain HTML inputs. This can lead to malicious code being executed when sanitizing HTML. To fix this, update to Justht...
7.5
free5gc UDR Exposes Subscriber Info Without Login
GHSA-wrwh-rpq4-87hf CVE-2026-40245
An attacker can access sensitive subscriber information by sending a simple HTTP request to the free5gc UDR service. This is a concern for businesses and individuals who rely on the free5gc service, a...
7.5
Windows HTTP.sys Denial-of-Service Vulnerability
CVE-2026-33096
An attacker can crash Windows HTTP.sys, disrupting network services. This affects Windows systems with HTTP.sys enabled. Patch your Windows systems to prevent potential service disruptions.
7.5
Denial of Service in .NET and Visual Studio
CVE-2026-32203
A flaw in .NET and Visual Studio could allow an attacker to crash a service and disrupt access to it. This could happen if a malicious user sends a specially crafted request to the service. To protect...
7.5
Windows LSASS Service Can Be Crashed Remotely
CVE-2026-32071
A flaw in Windows LSASS service can allow an attacker to crash the service, making it unavailable to legitimate users. This can happen when an attacker sends a specific packet to the service. To prote...
7.5
Windows Server Update Service Tampering Vulnerability
CVE-2026-26154
The Windows Server Update Service has a flaw that allows a hacker to manipulate data sent over a network. This could allow an attacker to disrupt the update process or introduce malicious code. You sh...
7.5