7.5

CVSS3.1

CVE-2026-35036 - Ech0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Feature

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a page title) through GET /api/website/title. That is legitimate product behavior, but the implementation is unsafe: the route is unauthenticated, accepts โ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:55 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 3:17 p.m.

7.2

CVSS3.1

CVE-2026-35035 - CI4MS Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for Aโ€ฆ

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0, the application fails to properly sanitize user-controlled input within System Settings โ€“ Company Information. Several administrative confโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:49 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

9.4

CVSS4.0

CVE-2026-35030 - LiteLLM has an authentication bypass via OIDC userinfo cache key collision

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20โ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:47 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

5.3

CVSS4.0

CVE-2026-5670 - Cyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload

A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This issue affects the function move_uploaded_file of the file /AssignmentSection/submission/upload.php. Performing a manipulation of the argument File results in unrestricted upload. Thโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:45 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 6:54 a.m.

8.7

CVSS4.0

CVE-2026-35029 - LiteLLM affected by privilege escalation via unrestricted proxy configuration endpoint

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environmenโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:35 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

7.1

CVSS4.0

CVE-2026-34992 - Missing Encryption of Sensitive Data in antrea.io/antrea

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encryption vulnerability affects inter-Node Pod traffic. In Antrea clusters configured for dual-stack networking with IPsec encryption enabled (trafficEncryptionMode: ipsec), Antrea failโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:31 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:10 p.m.

6.9

CVSS4.0

CVE-2026-5669 - Cyber-III Student-Management-System Parameter login.php sql injection

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible โ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:30 p.m. ๐Ÿ”„ Last Modified: April 6, 2026, 4:30 p.m.

9.4

CVSS4.0

CVE-2026-34989 - CI4MS affected by Profile & User Management Full Account Takeover for All-Roles & Privilege-Escalatโ€ฆ

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 31.0.0.0, the application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:25 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.

7.5

CVSS3.1

CVE-2026-34986 - Go JOSE affect by a panic in JWE decryption

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will paniโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:22 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:50 p.m.

5.8

CVSS3.1

CVE-2026-34981 - whisperX REST API: SSRF in download_from_url() โ€” URL validation happens after HTTP request, extensiโ€ฆ

The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url() in app/services/file_service.py calls requests.get(url) with zero URL validation. The file extension check occurs AFTER the HTTP request is already made, and can be bypassed byโ€ฆ

๐Ÿ“… Published: April 6, 2026, 4:19 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343924
Page 140 of 34,393
ยซ previous page ยป next page
Filters