5.3

CVSS3.1

CVE-2026-31888 - Shopware has user enumeration via distinct error codes on Store API login endpoint

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) or is unknown…

📅 Published: March 11, 2026, 6:53 p.m. 🔄 Last Modified: March 11, 2026, 6:53 p.m.

3.6

CVSS3.1

CVE-2026-24509 -

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

📅 Published: March 11, 2026, 6:51 p.m. 🔄 Last Modified: March 11, 2026, 6:51 p.m.

8.9

CVSS4.0

CVE-2026-31887 - Shopware unauthenticated data extraction possible through store-api.order endpoint

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1…

📅 Published: March 11, 2026, 6:49 p.m. 🔄 Last Modified: March 11, 2026, 6:49 p.m.

7.7

CVSS3.1

CVE-2026-31881 - Runtipi unauthenticated /api/auth/reset-password allows operator account takeover during active res…

Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, resulting in full account takeover. The endpoint POST /api/auth/reset-password is exposed without authentication/authorization …

📅 Published: March 11, 2026, 6:37 p.m. 🔄 Last Modified: March 11, 2026, 6:37 p.m.

5.1

CVSS4.0

CVE-2026-31879 - Frappe Workspace modification and stored XSS due to improper resource ownership checks

Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation and improper permission checks, users could modify other user's private workspaces. Specially crafted requests could lead to stored XSS here. This vulnerability is fixed in 14.100…

📅 Published: March 11, 2026, 6:34 p.m. 🔄 Last Modified: March 11, 2026, 6:34 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here