5.4

CVSS3.1

CVE-2026-29840 - Stored XSS in JiZhiCMS Release Function Allows Authenticated Script Injection

JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. The application attempts to sanitize input by filtering <script> tags but fails to recursively remove dangerous event handlers in other HTML tags (such…

📅 Published: March 24, 2026, midnight 🔄 Last Modified: March 26, 2026, 12:20 p.m.

4.3

CVSS3.1

CVE-2026-33290 - WPGraphQL Repo's updateComment allows low-privileged authenticated users to change comment moderati…

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment allows an authenticated low-privileged user (including a custom role with zero capabilities) to change moderation status of their own comment (for example to APPROVE) without the mo…

📅 Published: March 23, 2026, 11:58 p.m. 🔄 Last Modified: March 25, 2026, 8:40 p.m.

9.6

CVSS3.1

CVE-2026-33211 - Tekton Pipelines git resolver has path traversal that allows reading arbitrary files from the resol…

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permissi…

📅 Published: March 23, 2026, 11:55 p.m. 🔄 Last Modified: March 27, 2026, 9:21 a.m.

9.1

CVSS3.1

CVE-2026-33286 - Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary rel…

📅 Published: March 23, 2026, 11:52 p.m. 🔄 Last Modified: March 25, 2026, 8:40 p.m.

6.5

CVSS3.1

CVE-2026-33283 - Ella Core panics on malformed ULNASTransport Message without a Request Type

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Transport NAS messages without a Request Type. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connected subscrib…

📅 Published: March 23, 2026, 11:49 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-33282 - Ella Core panics on malformed NGAP Location Report

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` IE. An attacker able to send crafted NGAP message…

📅 Published: March 23, 2026, 11:47 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

6.5

CVSS3.1

CVE-2026-33281 - Ella Core panics on invalid PDU Session IDs in NGAP messages

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers…

📅 Published: March 23, 2026, 11:46 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

7.1

CVSS3.1

CVE-2026-33252 - MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrion

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Authorization, …

📅 Published: March 23, 2026, 11:44 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

8.7

CVSS4.0

CVE-2026-33241 - Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data Parsing

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending ext…

📅 Published: March 23, 2026, 11:41 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-33242 - Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraints and access unintended backend paths (e.g., prot…

📅 Published: March 23, 2026, 11:40 p.m. 🔄 Last Modified: March 25, 2026, 8:35 p.m.
Total resulsts: 340915
Page 134 of 34,092
« previous page » next page
Filters