Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 18 April 2026

RSS

130 vulnerabilities published on 18 April 2026

Severity:
libgphoto2: Camera driver library has a data leak
CVE-2026-40335
The libgphoto2 library is used to interact with cameras. A bug in older versions of this library could allow an attacker to access sensitive data. Update to version 2.5.34 or later to fix the issue.
5.2
Sentry kernel: Tasks can crash or leak data to other tasks
CVE-2026-40337
A bug in Sentry kernel versions before 0.4.7 allows a task with certain capabilities to talk to other tasks or crash the system. This could lead to denial of service or unauthorized data transfer. Upd...
5.1
ChurchCRM usernames can trigger malicious browser behavior
CVE-2026-40593
In ChurchCRM versions before 7.2.0, malicious usernames can cause unintended actions when viewed by an administrator. This could lead to unauthorized access or data theft. Update to version 7.2.0 or l...
4.8
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
GHSA-h39g-6x3c-7fq9
# Summary `SubFileSystem` fails to confine operations to its declared sub path when the input path is `/../` (or equivalents `/../`, `/..\\`). This path passes all validation but resolves to the root...
3.8
Libgphoto2 crashes when processing camera data from untrusted USB devices
CVE-2026-40341
Libgphoto2, a library for accessing and controlling cameras, has a bug that can cause it to crash when it receives bad data from an untrusted USB device. This could potentially be exploited by an atta...
3.5
Libgphoto2's Canon Camera Access Library May Crash or Expose Data
CVE-2026-40334
Libgphoto2's camera library has a bug that can cause it to crash or expose sensitive data when interacting with Canon cameras. This affects all versions up to and including 2.5.33. To fix the issue, u...
3.5
libgphoto2: Sony camera processing can leak memory
CVE-2026-40336
A memory leak exists in libgphoto2 when processing Sony cameras. This can cause the library to consume more and more memory over time, potentially leading to performance issues or crashes. Update to v...
2.4
Apache HTTP Server Unauthenticated Remote File Disclosure
MINI-m2pc-9p69-mqmh
Apache's HTTP server has a flaw that allows hackers to access sensitive files without a password. This can lead to unauthorized access to sensitive data. Update the server to the latest version to fix...
MINI-564m-hx4w-5pqh
MINI-564m-hx4w-5pqh
MINI-5vqw-779w-qvxj
MINI-5vqw-779w-qvxj
MINI-cx3g-2r7f-jfvc
MINI-cx3g-2r7f-jfvc
MINI-fjj5-7998-v8mj
MINI-fjj5-7998-v8mj
MINI-gjvh-cqjq-2rcc
MINI-gjvh-cqjq-2rcc
MINI-pv2p-c7rq-254f
MINI-pv2p-c7rq-254f
MINI-w7mp-g7jp-3qg8
MINI-w7mp-g7jp-3qg8
MINI-mvfx-pmq6-36qf
MINI-mvfx-pmq6-36qf
MINI-qvwf-mchc-g85g
MINI-qvwf-mchc-g85g
MINI-wv35-8wvq-765c
MINI-wv35-8wvq-765c
MINI-q8gf-67rc-p66c
MINI-q8gf-67rc-p66c
MINI-pmvw-9fpx-g69q
MINI-pmvw-9fpx-g69q
MINI-mxf7-jh32-cq22
MINI-mxf7-jh32-cq22
MINI-jjc9-m7c4-p47x
MINI-jjc9-m7c4-p47x
MINI-mvgp-xwrx-jp3g
MINI-mvgp-xwrx-jp3g
MINI-c2wq-3xfc-gch3
MINI-c2wq-3xfc-gch3
Apache HTTP Server Unauthenticated Remote Code Execution
MINI-h5j7-37p3-c97r
Apache's HTTP Server contains a vulnerability that allows an attacker to execute unauthorized code on a server without needing a password. This could lead to data theft, system compromise, or other ma...