3.4

CVSS3.1

CVE-2025-68467 - Dark Reader gives users the ability to request style sheets from local web servers

Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites different from the original…

📅 Published: March 4, 2026, 9:53 p.m. 🔄 Last Modified: March 18, 2026, 3:13 p.m.

9.3

CVSS4.0

CVE-2026-29000 - pac4j-jwt JwtAuthenticator Authentication Bypass

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT with…

📅 Published: March 4, 2026, 9:49 p.m. 🔄 Last Modified: April 16, 2026, 4:18 p.m.

8.6

CVSS4.0

CVE-2025-66024 - XWiki Blog Application home page vulnerable to Stored XSS via Post Title

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML <title> tag without…

📅 Published: March 4, 2026, 9:47 p.m. 🔄 Last Modified: April 21, 2026, 3:16 p.m.

5.4

CVSS3.1

CVE-2026-27898 - Vaultwarden: Unauthorized Access via Partial Update API on Another User’s Cipher

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies acce…

📅 Published: March 4, 2026, 9:44 p.m. 🔄 Last Modified: April 17, 2026, 1:15 p.m.

8.3

CVSS3.1

CVE-2026-27803 - Vaultwarden: Collection Management Operations Allowed Without `manage` Verification for Manager Role

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue h…

📅 Published: March 4, 2026, 9:40 p.m. 🔄 Last Modified: April 16, 2026, 1:15 p.m.

8.3

CVSS3.1

CVE-2026-27802 - Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.

📅 Published: March 4, 2026, 9:34 p.m. 🔄 Last Modified: April 17, 2026, 1:15 p.m.

6

CVSS4.0

CVE-2026-27801 - Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass t…

📅 Published: March 4, 2026, 9:32 p.m. 🔄 Last Modified: April 16, 2026, 1:15 p.m.

7.5

CVSS3.1

CVE-2026-28435 - Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized requ…

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or…

📅 Published: March 4, 2026, 7:36 p.m. 🔄 Last Modified: April 16, 2026, 1:15 p.m.

5.3

CVSS3.1

CVE-2026-28434 - cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and the application has not registered a custom exception handler via set_exception_handler(), the library catches the exception and writes its message di…

📅 Published: March 4, 2026, 7:34 p.m. 🔄 Last Modified: April 16, 2026, 1:15 p.m.

5.9

CVSS4.0

CVE-2026-28427 - OpenDeck affected by path traversal allows arbitrary file read

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request path, an attacker can traverse outside the intended directo…

📅 Published: March 4, 2026, 7:30 p.m. 🔄 Last Modified: April 21, 2026, 3:17 p.m.
Total resulsts: 349182
Page 1338 of 34,919
« previous page » next page
Filters