4.2
CVE-2026-32187 - Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
Microsoft Edge (Chromium-based) Defense in Depth Vulnerability
5.4
CVE-2026-33887 - Statamic allows unauthorized content access through missing authorization in its revision controlleβ¦
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the aβ¦
6.5
CVE-2026-33886 - Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their contβ¦
6.1
CVE-2026-33885 - Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions anβ¦
4.3
CVE-2026-33884 - Statamic's live preview token bypasses content protection for unrelated entries
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16β¦
6.1
CVE-2026-33883 - Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser.β¦
6.5
CVE-2026-33882 - Statamic's Markdown preview endpoint exposes sensitive user data
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, an authenticated control panel user could retrievβ¦
7.3
CVE-2026-33881 - Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable interβ¦
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals without escaping single quotes in the NativeTS executor. A workspace admin who sets a custom environment β¦
2.7
CVE-2026-33879 - FLIP doesn't have rate limiting or brute-force protection on login
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-β¦
8.7
CVE-2026-4976 - Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and coβ¦