7.1

CVSS3.1

CVE-2026-29778 - pyLoad: Arbitrary File Write via Path Traversal in edit_package()

pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the edit_package() function implements insufficient sanitization for the pack_folder parameter. The current protection relies on a single-pass string replacement of "../", which can be …

πŸ“… Published: March 7, 2026, 3:28 p.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

2.1

CVSS4.0

CVE-2026-29781 - Sliver: Authenticated Nil-Pointer Dereference in Handlers

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nes…

πŸ“… Published: March 7, 2026, 3:25 p.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

5.5

CVSS3.1

CVE-2026-29780 - eml_parser: Path Traversal in Official Example Script Leading to Arbitrary File Write

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to version 2.0.1, the official example script examples/recursively_extract_attachments.py contains a path traversal vulnerability that allows arbit…

πŸ“… Published: March 7, 2026, 3:22 p.m. πŸ”„ Last Modified: April 16, 2026, 11 a.m.

7.5

CVSS3.1

CVE-2026-29779 - UptimeFlare: Montior config / Credentials in `workerConfig` exposed in client-side JavaScript bundle

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.ts exports both pageConfig (safe for client use) and workerConfig (server-only, contains sensitive data) from the same module. Due to pages/…

πŸ“… Published: March 7, 2026, 3:19 p.m. πŸ”„ Last Modified: April 18, 2026, 10 a.m.

4.1

CVSS3.1

CVE-2026-29190 - Karapace: Path Traversal in Backup Reader

Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Traversal vulnerability in the backup reader (backup/backends/v3/backend.py). If a malicious backup file is provided to Karapace, an attacker may exploit insufficient path validation…

πŸ“… Published: March 7, 2026, 3:16 p.m. πŸ”„ Last Modified: April 16, 2026, 11 a.m.

8.7

CVSS4.0

CVE-2026-29771 - Netmaker: Denial of Service via Server Shutdown Endpoint

Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart inter…

πŸ“… Published: March 7, 2026, 3:14 p.m. πŸ”„ Last Modified: April 16, 2026, 11 a.m.

8.1

CVSS3.1

CVE-2026-29067 - ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login

ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password reset …

πŸ“… Published: March 7, 2026, 3:12 p.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

8.2

CVSS3.1

CVE-2026-29193 - ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V2

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login V2 UI allowed users to bypass login behavior and security policies and self-register new accounts or sign in using password even if corresponding options were disabled in their o…

πŸ“… Published: March 7, 2026, 3:11 p.m. πŸ”„ Last Modified: April 16, 2026, 11 a.m.

7.7

CVSS3.1

CVE-2026-29192 - ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via Default URI Redirect. This issue has been patched in version 4.12.0.

πŸ“… Published: March 7, 2026, 3:09 p.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

9.3

CVSS3.1

CVE-2026-29191 - ZITADEL: 1-Click Account Takeover via XSS in /saml-post Endpoint

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.

πŸ“… Published: March 7, 2026, 3:07 p.m. πŸ”„ Last Modified: April 16, 2026, 11 a.m.
Total resulsts: 346636
Page 1008 of 34,664
Β« previous page Β» next page
Filters