9.3

CVSS3.1

CVE-2026-32754 - FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in the database without sanitization and rendered unes…

πŸ“… Published: March 19, 2026, 9:35 p.m. πŸ”„ Last Modified: March 23, 2026, 7:14 p.m.

6.9

CVSS4.0

CVE-2026-27935 - Discourse leaks private topic metadata to non-authorized users

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not have access to the private topics. Versions 2026…

πŸ“… Published: March 19, 2026, 9:33 p.m. πŸ”„ Last Modified: March 23, 2026, 8:18 p.m.

8.5

CVSS4.0

CVE-2026-32753 - FreeScout: Stored XSS through SVG file upload with filter bypass

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of .png with content type of image/svg+…

πŸ“… Published: March 19, 2026, 9:26 p.m. πŸ”„ Last Modified: March 23, 2026, 7:25 p.m.

0

CVSS3.1

CVE-2026-32752 - FreeScout: Broken Access Control in ThreadPolicy β€” Any User Can Read/Edit All Customer Messages

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a broken access control vulnerability that allows any authenticated user (regardless of role or mailbox access) to read and modify all customer-…

πŸ“… Published: March 19, 2026, 9:21 p.m. πŸ”„ Last Modified: March 23, 2026, 7:30 p.m.

9.8

CVSS3.1

CVE-2026-32194 - Microsoft Bing Images Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

πŸ“… Published: March 19, 2026, 9:21 p.m. πŸ”„ Last Modified: March 24, 2026, 4:49 p.m.

1.2

CVSS4.0

CVE-2026-4159 - wc_PKCS7_DecodeEnvelopedData 1 byte out-of-bounds read

1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be triggered by a crafted CMS EnvelopedData message with zero-length encrypted c…

πŸ“… Published: March 19, 2026, 9:17 p.m. πŸ”„ Last Modified: March 20, 2026, 4:29 p.m.

8.7

CVSS4.0

CVE-2026-27934 - Discourse leaks private topic title and post excerpt via user action API endpoint

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized users, leading to information disclosure. Versions 2…

πŸ“… Published: March 19, 2026, 9:17 p.m. πŸ”„ Last Modified: March 20, 2026, 6:53 p.m.

6.8

CVSS3.1

CVE-2026-32750 - SiYuan importStdMd: unvalidated localPath imports arbitrary host directories as persistent notes

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFromLocalPath with zero path validation. The function recursively reads every file under the given path and permanently stores their con…

πŸ“… Published: March 19, 2026, 9:15 p.m. πŸ”„ Last Modified: March 23, 2026, 6:09 p.m.

5.1

CVSS4.0

CVE-2026-32751 - SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket events. The desktop version (Files.ts) properly uses escapeHtml() for the same ope…

πŸ“… Published: March 19, 2026, 9:11 p.m. πŸ”„ Last Modified: March 24, 2026, 1:42 a.m.

7.6

CVSS3.1

CVE-2026-32749 - SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside…

πŸ“… Published: March 19, 2026, 9:07 p.m. πŸ”„ Last Modified: March 23, 2026, 6:08 p.m.
Total resulsts: 339922
Page 119 of 33,993
Β« previous page Β» next page
Filters