Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 16 April 2026
RSS962 vulnerabilities published on 16 April 2026
Severity:
Saltcorn: Unauthorized Access to Database Possible Through SQL Injection
GHSA-jp74-mfrx-3qvh
An attacker with a user account can access and modify sensitive data in the database, potentially exposing passwords and other confidential information. This is because the Saltcorn application does n...
10.0
Paperclip API: Access to Other Companies' Agent Keys
GHSA-3xx2-mqjm-hg9x
Attackers with limited access to one company can access, create, or delete agent keys for any agent in any other company. This allows them to gain full access to the compromised company's agents. To f...
10.0
Any authenticated user can access any company's agents
GHSA-47wq-cj9q-wpmp
An authenticated user can access and generate API tokens for any company's agents, without proper authorization. This allows unauthorized access to sensitive data and actions. To fix this, update your...
10.0
Flowise: Authenticated User Can Execute OS Commands
GHSA-c9gw-hvqq-f33r
CVE-2026-40933
An attacker can execute arbitrary system commands on a Flowise server by creating a custom MCP with a malicious command. This requires a valid Flowise account and access to the server. To fix, update ...
10.0
iSherlock by HGiga Allows Unauthenticated Attackers to Execute Commands
CVE-2026-6349
The iSherlock software by HGiga has a security flaw that lets attackers with no login access inject malicious commands and run them on the server. This could be exploited by hackers to gain control of...
10.0
Froxlor API: Language Parameter Allows Malicious File Access
GHSA-w59f-67xm-rxx7
Froxlor's API for updating customer and admin settings has a security issue. An attacker can access and execute arbitrary files on the system by manipulating the language setting. To fix this, update ...
10.0
CloneSite plugin in WWBN AVideo allows attackers to run malicious code
GHSA-xr6f-h4x7-r6qp
The CloneSite plugin in WWBN AVideo has a security flaw that allows attackers to execute malicious code on the server. This happens when an attacker tricks the plugin into running a malicious URL, whi...
9.9
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
GHSA-w59f-67xm-rxx7
## Summary
The Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can...
9.9
Authentik's OAuth Redirect URI Checks Can Be Bypassed
CVE-2024-52289
BIT-authentik-2024-52289
Authentik's open-source identity provider has a flaw in its OAuth2 redirect URI checks. If a provider is not configured with any redirect URIs, an attacker can register a domain that resembles a valid...
7.9
Paperclip AI v2026.403.0: Unauthorized Command Execution
GHSA-vr7g-88fq-vhq3
Paperclip's execution workspace lifecycle has a security flaw that lets attackers inject malicious commands into the system. This can happen when updating a workspace in certain deployment modes, allo...
9.8
Electerm Installer Command Injection on macOS and Linux
GHSA-wxw2-rwmh-vr8f
Users who install Electerm globally with npm are at risk of arbitrary command execution and file tampering. An attacker can exploit this vulnerability by controlling the Electerm update server to run ...
9.8
Electerm Installer Allows Hackers to Run Malicious Commands
GHSA-wxw2-rwmh-vr8f
The Electerm installer has a security flaw that lets hackers execute malicious commands on your computer if you install it using npm. This is a serious risk for anyone who uses Electerm. To stay safe,...
9.8
Pay-uz Laravel Package Exposes Payment Files to Unauthenticated Attacks
CVE-2026-31843
GHSA-m5wg-cjgh-223j
The pay-uz Laravel package has a security flaw that lets hackers change important payment files without a password. This could allow attackers to take control of your website's payment system. Update ...
10.0
SQL Injection in Vehicle Parking Area Management System
CVE-2026-37345
The Vehicle Parking Area Management System v1.0 may allow attackers to access sensitive data or take control of the system if they inject malicious SQL code. This could happen if someone enters specia...
9.8
WordPress Riaxe Product Customizer plugin allows attackers to steal control
CVE-2026-3596
The Riaxe Product Customizer plugin for WordPress is vulnerable, allowing hackers to gain control of your site without a password. This could lead to unauthorized changes, including enabling user regi...
9.8
MailGates/MailAudit Buffer Overflow Allows Remote Takeover
CVE-2026-6350
The MailGates/MailAudit program has a security flaw that could allow an attacker to take control of the program and execute unauthorized code. This could happen if an attacker sends a malicious messag...
9.3
Creolabs Gravity 0.9.5 and earlier: Malicious scripts can crash or take control
CVE-2026-40504
Creolabs Gravity, a server software, has a bug in its script execution that can be exploited by crafting special scripts. This can cause the software to crash or allow an attacker to execute malicious...
9.3
UEFI Firmware Parser May Crash or Allow Malicious Code Execution
GHSA-hm2w-vr2p-hq7w
The UEFI Firmware Parser has a flaw that can cause a crash or allow an attacker to run malicious code on a computer. This issue affects the UEFI Firmware Parser, a tool used to work with UEFI firmware...
9.8
UEFI Firmware Parser Can Crash or Allow Malicious Code Execution
GHSA-hm2w-vr2p-hq7w
The UEFI Firmware Parser contains a vulnerability that can cause a crash or potentially allow malicious code to be executed. This issue affects systems that use the Tiano decompressor. To protect your...
9.8
UEFI Firmware Parser Can Crash or Be Hacked
GHSA-2689-5p89-6j3j
The UEFI Firmware Parser is prone to a critical flaw that can cause it to crash or be exploited by hackers. This is due to a bug in how it handles certain types of firmware data. To fix this, the deve...
9.8
UEFI Firmware Parser Can Crash or Be Exploited by Malicious Firmware
GHSA-2689-5p89-6j3j
A vulnerability in the UEFI Firmware Parser can cause the program to crash or allow an attacker to execute malicious code on a computer. This happens when the parser processes a specially crafted firm...
9.8
Microsoft QUIC: Unauthorized Privilege Elevation Over Network
GHSA-gvvw-8j96-8g5r
CVE-2026-32179
An attacker can exploit a weakness in Microsoft QUIC to gain elevated privileges over a network. This affects how Microsoft QUIC handles certain types of data it receives. To protect your system, appl...
9.8
Authentik Token Exposed in URL
CVE-2025-52553
BIT-authentik-2025-52553
A security issue exists in older versions of Authentik, an open-source identity provider. If a malicious person gets the URL from a shared screen, they could potentially access the same session. To st...
5.5
Malicious Code Execution in protobufjs
GHSA-xq3m-2v4x-88gg
Attackers can execute arbitrary code by manipulating protobuf definitions, potentially allowing them to take control of your website or server. This happens if an attacker can influence the protobuf d...
9.4
Flowise: Passwords Can Be Changed Without a Login
GHSA-f6hc-c5jr-878p
Flowise, a tool for building AI applications, has a security problem that allows hackers to change user passwords without needing a login. This means that an attacker can gain access to a user's accou...
9.4