6.9

CVSS4.0

CVE-2026-33993 - Locutus has Prototype Pollution via __proto__ Key Injection in unserialize()

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation without filtering the `__proto__` key. When a PHP seri…

📅 Published: March 27, 2026, 10:14 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

9.3

CVSS4.0

CVE-2026-33992 - pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF) attacks. An authenticated attacker can exploit this to access internal network service…

📅 Published: March 27, 2026, 10:12 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

8.8

CVSS3.1

CVE-2026-33991 - WeGIA has SQL Injection in deletar_tag.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` variable into SQL queries on lines 16-17 without prepared statements or sanitization. Version 3.6.7 …

📅 Published: March 27, 2026, 10:10 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

5.3

CVSS3.1

CVE-2026-33936 - python-ecdsa: Denial of Service via improper DER length validation in crafted private keys

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low…

📅 Published: March 27, 2026, 10:08 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

5.3

CVSS4.0

CVE-2026-4992 - wandb OpenUI HTMLAnnotator server.py get_share HTML injection

A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulation of the argument ID can lead to HTML injection. The attack may be performed from remote. The explo…

📅 Published: March 27, 2026, 10:03 p.m. 🔄 Last Modified: March 28, 2026, 6:37 a.m.

5.1

CVSS4.0

CVE-2026-4991 - QDOCS Smart School Management System Admission Enquiry enquiry cross site scripting

A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The attack is possible to…

📅 Published: March 27, 2026, 10:03 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

8.1

CVSS3.1

CVE-2026-33989 - @mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture too…

Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Traversal vulnerability in the `mobile_save_screenshot` and `mobile_start_screen_recording` tools. The `saveTo` and `output` parameters were passed direct…

📅 Published: March 27, 2026, 10:03 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.3

CVSS4.0

CVE-2026-33981 - Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which reads all process environment variables and stores them as the watch snapshot. An authenticated user (or unauthenticat…

📅 Published: March 27, 2026, 10:01 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.3

CVSS3.1

CVE-2026-33980 - Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitr…

Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabil…

📅 Published: March 27, 2026, 9:32 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.2

CVSS3.1

CVE-2026-33979 - Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS r…

Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has been identified in versions prior to 2.0.2 where restrictive sanitization configurations are…

📅 Published: March 27, 2026, 9:29 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.
Total resulsts: 341065
Page 11 of 34,107
« previous page » next page
Filters