8.2

CVSS4.0

CVE-2026-27601 - Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untr…

📅 Published: March 3, 2026, 10:38 p.m. 🔄 Last Modified: April 28, 2026, 3:06 p.m.

9.1

CVSS3.1

CVE-2026-26279 - Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adm…

📅 Published: March 3, 2026, 10:31 p.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

8.3

CVSS4.0

CVE-2026-3266 - Improper access control vulnerability has been discovered in OpenText™ Filr.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

📅 Published: March 3, 2026, 10:28 p.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

7.4

CVSS3.1

CVE-2026-27981 - HomeBox has an Auth Rate Limit Bypass via IP Spoofing

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-For header, and 3. r.RemoteAddr (TCP connection ad…

📅 Published: March 3, 2026, 10:27 p.m. 🔄 Last Modified: April 18, 2026, 10:15 a.m.

5

CVSS3.1

CVE-2026-27600 - HomeBox affected by Blind SSRF

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although t…

📅 Published: March 3, 2026, 10:23 p.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

4.6

CVSS3.1

CVE-2026-26272 - HomeBox affected by Stored XSS via HTML/SVG Attachment Upload

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malic…

📅 Published: March 3, 2026, 10:20 p.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

9.3

CVSS3.1

CVE-2026-26266 - AliasVault affected by Cross-Site Scripting (XSS) via Email HTML Rendering

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in …

📅 Published: March 3, 2026, 10:16 p.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

4.5

CVSS3.1

CVE-2026-25590 - GLPI Inventory Plugin has Reflected XSS in task jobs

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.

📅 Published: March 3, 2026, 10:14 p.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

10

CVSS3.1

CVE-2026-24898 - OpenEMR has an Unauthenticated MedEx Token Disclosure

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to complete…

📅 Published: March 3, 2026, 10:10 p.m. 🔄 Last Modified: April 16, 2026, 2 p.m.

9.6

CVSS3.1

CVE-2026-25146 - OpenEMR's payments gateway_api_key secret rendered into client JS code

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary…

📅 Published: March 3, 2026, 10:08 p.m. 🔄 Last Modified: April 16, 2026, 2 p.m.
Total resulsts: 349182
Page 1357 of 34,919
« previous page » next page
Filters