7.5

CVSS3.1

CVE-2026-33285 - LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mechanism can be completely bypassed by using reverse range expressions (e.g., `(100000000..1)`), allowing an attacker to allocate unlimited memory. Combin…

📅 Published: March 26, 2026, 12:34 a.m. 🔄 Last Modified: March 30, 2026, 8:57 p.m.

7.5

CVSS3.1

CVE-2026-33287 - LiquidJS has Exponential Memory Amplification through its replace_first Filter $& Pattern

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS uses JavaScript's `String.prototype.replace()` which interprets `$&` as a back reference to the matched substring. The filter only charges `memoryLimi…

📅 Published: March 26, 2026, 12:33 a.m. 🔄 Last Modified: March 30, 2026, 8:57 p.m.

8.1

CVSS4.0

CVE-2026-33942 - Saloon has insecure deserialization in AccessTokenAuthenticator (object injection / RCE)

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed_classes => true. An attacker who can control the serialized…

📅 Published: March 26, 2026, 12:27 a.m. 🔄 Last Modified: March 28, 2026, 2:06 a.m.

8

CVSS4.0

CVE-2026-33183 - Saloon has a Fixture Name Path Traversal Vulnerability

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file paths under the configured fixture directory without validation. A name containing path segments (e.g. ../traversal or ../../etc/passwd) resulted in a pat…

📅 Published: March 26, 2026, 12:25 a.m. 🔄 Last Modified: March 30, 2026, 8:57 p.m.

6.6

CVSS4.0

CVE-2026-33182 - Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building the request URL, Saloon combined the connector's base URL with the request endpoint. If the endpoint was a valid absolute URL, the code used that URL as-is and ignored the base U…

📅 Published: March 26, 2026, 12:22 a.m. 🔄 Last Modified: March 30, 2026, 8:57 p.m.

6.3

CVSS4.0

CVE-2026-4830 - kalcaddle kodbox Public Share userShare.class.php add privilege escalation

A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipulation leads to unrestricted upload. The attack can be executed remotely. This attack is characteriz…

📅 Published: March 26, 2026, 12:18 a.m. 🔄 Last Modified: March 30, 2026, 1:26 p.m.

9.2

CVSS4.0

CVE-2026-33526 - Squid vulnerable to Denial of Service in ICP Request handling

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protoco…

📅 Published: March 26, 2026, 12:16 a.m. 🔄 Last Modified: March 31, 2026, 1:18 a.m.

6.9

CVSS4.0

CVE-2026-33515 - Squid has issues in ICP message handling

Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive information when responding wi…

📅 Published: March 26, 2026, 12:13 a.m. 🔄 Last Modified: March 31, 2026, 1:22 a.m.

8.7

CVSS4.0

CVE-2026-32748 - Squid has Denial of Service in ICP Response handling

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Deni…

📅 Published: March 26, 2026, 12:11 a.m. 🔄 Last Modified: March 27, 2026, 9:29 a.m.

6.1

CVSS3.1

CVE-2026-29933 -

A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referrer value in the request header.

📅 Published: March 26, 2026, midnight 🔄 Last Modified: March 30, 2026, 8:57 p.m.
Total resulsts: 341473
Page 101 of 34,148
« previous page » next page
Filters