Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 19 April 2026

RSS

40 vulnerabilities published on 19 April 2026

Severity:
Authlib: Malicious JWTs Can Bypass Security Checks in Older Versions
CVE-2026-28802 GHSA-7wc2-qxgw-g8gg ECHO-579f-8639-173e
Older versions of Authlib, a library used to build OAuth and OpenID Connect servers, can be tricked into accepting fake security tokens. This could allow attackers to bypass security checks. Update to...
8.3
Authlib JWS Forgery: Attackers Can Bypass Authentication
GHSA-wvwj-cvrp-7pv5 CVE-2026-27962 ECHO-e780-297e-3c37
A security flaw in Authlib's JWS (JSON Web Signature) feature allows attackers to create fake tokens that can trick servers into accepting them as genuine. This bypasses authentication and authorizati...
9.1
H3C Magic B1: Remote Code Execution Through Buffer Overflow
CVE-2026-6563
A security flaw in H3C Magic B1 allows an attacker to execute malicious code on the device by manipulating a specific argument. This could give the attacker control over the device. The vendor has not...
7.4
H3C Magic B0: Remote Access to Sensitive Data
CVE-2026-6560
A security flaw in H3C Magic B0 allows an attacker to potentially access sensitive data remotely. This can happen if an attacker manipulates certain data sent to the router. We recommend that H3C Magi...
7.4
Thunderbird Update Fixes Critical Security Risks
RLSA-2026:8459
Thunderbird users should update to the latest version to prevent hackers from executing malicious code or stealing sensitive information. This update fixes several security bugs that could allow attac...
8.8
ECHO-435f-9eb9-99cb
GHSA-m344-f55w-2m6j CVE-2026-28498 ECHO-435f-9eb9-99cb
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation ...
7.8
.NET Framework: Critical Security Updates Available
RLSA-2026:8471
New versions of .NET are available to fix four serious security issues, including the ability for attackers to bypass security, cause denial of service, or inject malicious code into email. The update...
7.5
Important: .NET 9.0 security update to prevent attacks and crashes
RLSA-2026:8474
.NET version 9.0 has security updates to protect against malicious attacks and system crashes. These updates are important for anyone using .NET to prevent data breaches and ensure smooth system opera...
7.5
FreeRDP: Remote Code Execution and Denial of Service Risk
RLSA-2026:8457
FreeRDP, a tool for connecting to remote desktops, has a security weakness that could allow hackers to inject malicious code or crash the connection. This could happen if a hacker sends a specially cr...
7.5
.NET 8.0 Security Update Available to Fix Multiple Risks
RLSA-2026:8469
If you're using .NET, update to .NET SDK 8.0.126 and .NET Runtime 8.0.26 to fix four security risks that could allow hackers to crash your system or bypass security controls. This update is available ...
7.5
Important: libarchive can expose sensitive data or run malicious code
RLSA-2026:8510
Libarchive, used in popular file managers and tools like bsdtar, contains two security flaws that could allow attackers to access sensitive information or execute malicious code. This affects users wh...
7.5
LightPicture API Upload Vulnerability: Exposes Sensitive Credentials
CVE-2026-6574
A security issue in LightPicture's API Upload Endpoint can leak hardcoded credentials. This affects versions up to 1.2.2. To protect your data, update to a fixed version of LightPicture as soon as pos...
6.9
KodExplorer File Sharing Feature Allows Unauthorized Access
CVE-2026-6569
An outdated version of KodExplorer (up to 4.52) makes it possible for attackers to access files without authentication. This is a serious issue because it could allow unauthorized access to sensitive ...
6.9
KodExplorer Share Feature Allows Remote File Access
CVE-2026-6568
A weakness in KodExplorer's share feature allows hackers to access files outside of the intended path. This means they could read or modify sensitive data on your server. Update to KodExplorer version...
6.9
Dameng100 muucmf 1.9.5.20260309: SQL Injection in Search Function
CVE-2026-6562
A security flaw in Dameng100 muucmf 1.9.5.20260309 allows an attacker to manipulate search results by injecting malicious code. This could potentially allow unauthorized access to sensitive data. We r...
6.9
Authlib Exposes Sensitive Data via Cryptographic Padding Oracle
GHSA-7432-952r-cw78 CVE-2026-28490 ECHO-c9a3-95ec-f0d8
The Authlib library in certain configurations allows attackers to determine the validity of JSON Web Encryption (JWE) padding, potentially exposing sensitive data. This issue is present in any Authlib...
8.1
EMC Calendly Plugin for WordPress allows attackers to inject malicious code
CVE-2026-0868
The EMC Calendly Plugin for WordPress is not properly securing user input, allowing an attacker with contributor-level access to inject malicious code into pages. This could lead to unauthorized actio...
6.4
PHPEMS 11.0: Malicious File Upload Can Hijack Server Requests
CVE-2026-6573
The PHPEMS 11.0 Instant Exam Creation Handler can be tricked into accepting and processing malicious files, allowing an attacker to control the server remotely. This could potentially lead to unauthor...
5.3
KodExplorer allows unauthorized access to sensitive data
CVE-2026-6571
A security flaw in KodExplorer 4.52 allows hackers to bypass access controls and gain unauthorized access to sensitive data. This could be exploited remotely by an attacker. Users should update to the...
5.3
Collabora KodExplorer File Upload Authorization Bypass
CVE-2026-6572
Collabora KodExplorer's file upload feature has a security flaw that allows unauthorized access. This means that someone could upload files without permission, potentially leading to data breaches or ...
6.3
EyouCMS allows remote attackers to upload files without restriction
CVE-2026-6561
An attacker can upload any file to EyouCMS without restrictions, which could allow them to install malware or disrupt the website's functionality. This is a serious issue because it could lead to unau...
5.1
EMQX Enterprise Session Handling Allows Unauthorized Access
CVE-2026-6564
EMQX Enterprise versions up to 6.1.0 have a security issue that could allow unauthorized access to user sessions. This means an attacker may be able to perform actions on behalf of other users without...
5.3
Wavlink WL-WN579A3 Router Login Page Has a Security Flaw
CVE-2026-6559
A security flaw in the login page of the Wavlink WL-WN579A3 router can allow hackers to inject malicious code into the page. This could potentially let them take control of the router or steal sensiti...
5.3
KodExplorer 4.52 allows attackers to bypass security checks remotely
CVE-2026-6570
The KodExplorer software up to version 4.52 has a security flaw that allows attackers to bypass security checks. This means that hackers can potentially access parts of the system they shouldn't be ab...
5.1
MINI-cc9v-qrp4-jg27
MINI-cc9v-qrp4-jg27