5.4

CVSS3.1

CVE-2026-33887 - Statamic allows unauthorized content access through missing authorization in its revision controlle…

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the a…

πŸ“… Published: March 27, 2026, 8:41 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-33886 - Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their cont…

πŸ“… Published: March 27, 2026, 8:40 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.1

CVSS3.1

CVE-2026-33885 - Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions an…

πŸ“… Published: March 27, 2026, 8:39 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

4.3

CVSS3.1

CVE-2026-33884 - Statamic's live preview token bypasses content protection for unrelated entries

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16…

πŸ“… Published: March 27, 2026, 8:38 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.1

CVSS3.1

CVE-2026-33883 - Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the `user:reset_password_form` tag could render user-input directly into HTML without escaping, allowing an attacker to craft a URL that executes arbitrary JavaScript in the victim's browser.…

πŸ“… Published: March 27, 2026, 8:37 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-33882 - Statamic's Markdown preview endpoint exposes sensitive user data

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be manipulated to return augmented data from arbitrary fieldtypes. With the users fieldtype specifically, an authenticated control panel user could retriev…

πŸ“… Published: March 27, 2026, 8:36 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.3

CVSS4.0

CVE-2026-33881 - Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable inter…

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals without escaping single quotes in the NativeTS executor. A workspace admin who sets a custom environment …

πŸ“… Published: March 27, 2026, 8:34 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

2.7

CVSS4.0

CVE-2026-33879 - FLIP doesn't have rate limiting or brute-force protection on login

Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-…

πŸ“… Published: March 27, 2026, 8:31 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

8.7

CVSS4.0

CVE-2026-4976 - Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and co…

πŸ“… Published: March 27, 2026, 8:29 p.m. πŸ”„ Last Modified: March 27, 2026, 11:17 p.m.

9.3

CVSS3.1

CVE-2026-33875 - Authenticator Vulnerable to Authentication Flow Hijack

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gemati…

πŸ“… Published: March 27, 2026, 8:25 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.
Total resulsts: 341037
Page 12 of 34,104
Β« previous page Β» next page
Filters