8.3

CVSS4.0

CVE-2026-33981 - Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include filter expressions allow use of the jq `env` builtin, which reads all process environment variables and stores them as the watch snapshot. An authenticated user (or unauthenticat…

📅 Published: March 27, 2026, 10:01 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.3

CVSS3.1

CVE-2026-33980 - Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitr…

Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabil…

📅 Published: March 27, 2026, 9:32 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.2

CVSS3.1

CVE-2026-33979 - Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS r…

Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.headers and req.params) to prevent Cross Site Scripting (XSS) attack. A vulnerability has been identified in versions prior to 2.0.2 where restrictive sanitization configurations are…

📅 Published: March 27, 2026, 9:29 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.6

CVSS3.1

CVE-2026-33955 - Notesnook vulnerable to RCE via stored XSS in Note History diff viewer

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using…

📅 Published: March 27, 2026, 9:27 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

6.9

CVSS4.0

CVE-2026-4990 - chatwoot Signup Endpoint login improper authorization

A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to improper authorization. The attack can be executed r…

📅 Published: March 27, 2026, 9:27 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

6.3

CVSS4.0

CVE-2026-4988 - Open5GS CCA Message smf_s6b denial of service

A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6b of the component CCA Message Handler. The manipulation results in denial of service. The attack may be launched remotely. Attacks of this nature are highly complex. The exploita…

📅 Published: March 27, 2026, 9:27 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

5.3

CVSS4.0

CVE-2026-4985 - dloebl CGIF GIF Image cgif.c cgif_addframe integer overflow

A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the file src/cgif.c of the component GIF Image Handler. The manipulation of the argument width/height leads to integer overflow. The attack may be initiated remotely. The identifier o…

📅 Published: March 27, 2026, 9:27 p.m. 🔄 Last Modified: March 27, 2026, 11:17 p.m.

9.7

CVSS3.1

CVE-2026-33976 - Notesnook vulnerable to RCE via stored XSS in Web Clipper rendering

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source …

📅 Published: March 27, 2026, 9:26 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

6.5

CVSS3.1

CVE-2026-33954 - LinkAce discloses private notesto unauthorized authenticated users via the web link detail page

LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-private link can be disclosed to a different authenticated user via the web interface. The API appears to correctly enforce note visibility, but the web link detail page renders n…

📅 Published: March 27, 2026, 9:23 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.

8.5

CVSS3.1

CVE-2026-33953 - LinkAce's SSRF protection can be bypassed via internal hostname resolution in LinkAce

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to …

📅 Published: March 27, 2026, 9:22 p.m. 🔄 Last Modified: March 27, 2026, 10:16 p.m.
Total resulsts: 341068
Page 12 of 34,107
« previous page » next page
Filters