9.1

CVSS3.1

CVE-2026-30458 -

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

๐Ÿ“… Published: March 26, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 8:57 p.m.

6.2

CVSS3.1

CVE-2026-23398 - icmp: fix NULL pointer dereference in icmp_tag_validation()

In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_validation() icmp_tag_validation() unconditionally dereferences the result of rcu_dereference(inet_protos[proto]) without checking for NULL. The inet_protos[] array is sparse -- onlyโ€ฆ

๐Ÿ“… Published: March 26, 2026, midnight ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

0

CVSS3.1

CVE-2026-30892 - Crun incorrectly parses `crun exec` option `-u`, leading to privilege escalation

crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectly parsed. The value `1` is interpreted as UID 0 and GID 0 when it should have been UID 1 and GID 0. The process thus runs with higher privileges thanโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:57 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:29 p.m.

7.7

CVSS3.1

CVE-2026-34056 - OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper authorization checks. Thโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:53 p.m. ๐Ÿ”„ Last Modified: March 28, 2026, 1:53 a.m.

8.1

CVSS3.1

CVE-2026-34055 - OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note belongs to a patient theโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:49 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.1

CVSS3.1

CVE-2026-34053 - OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless of role, to irreverโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:46 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

5.4

CVSS3.1

CVE-2026-34051 - OpenEMR has Improper ACL On Import/Export Popup

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulationโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: March 28, 2026, 1:52 a.m.

4.3

CVSS3.1

CVE-2026-33934 - OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signaturโ€ฆ

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of anโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:41 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

6.1

CVSS3.1

CVE-2026-33933 - Reflected XSS via Unescaped contextName Parameter in Custom Template Editor

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript inโ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:40 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:29 a.m.

7.6

CVSS3.1

CVE-2026-33932 - OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a โ€ฆ

๐Ÿ“… Published: March 25, 2026, 11:37 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 2:56 p.m.
Total resulsts: 341475
Page 103 of 34,148
ยซ previous page ยป next page
Filters