7.5

CVSS3.1

CVE-2026-33242 - Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraints and access unintended backend paths (e.g., prot…

📅 Published: March 23, 2026, 11:40 p.m. 🔄 Last Modified: March 25, 2026, 8:35 p.m.

6.9

CVSS4.0

CVE-2026-4615 - SourceCodester Online Catering Reservation search.php sql injection

A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the file /search.php. Such manipulation of the argument rcode leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

📅 Published: March 23, 2026, 11:38 p.m. 🔄 Last Modified: March 24, 2026, 10:29 a.m.

5.3

CVSS4.0

CVE-2026-4614 - itsourcecode sanitize or validate this input Parameter subjects.php sql injection

A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carrie…

📅 Published: March 23, 2026, 11:38 p.m. 🔄 Last Modified: March 24, 2026, 6:40 p.m.

7.5

CVSS3.1

CVE-2026-33250 - Crash when receiving specially-crafted packets

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public server. A malicious server can use this to crash the game on the player's …

📅 Published: March 23, 2026, 11:38 p.m. 🔄 Last Modified: March 25, 2026, 8:35 p.m.

6.6

CVSS4.0

CVE-2026-33202 - Rails Active Storage has possible glob injection in its DiskService

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled…

📅 Published: March 23, 2026, 11:34 p.m. 🔄 Last Modified: March 25, 2026, 8:35 p.m.

8

CVSS4.0

CVE-2026-33195 - Rails Active Storage has possible Path Traversal in DiskService

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path tr…

📅 Published: March 23, 2026, 11:31 p.m. 🔄 Last Modified: March 25, 2026, 8:35 p.m.

6.6

CVSS4.0

CVE-2026-33176 - Rails Active Support has a possible DoS vulnerability in its number helpers

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing scientific notation (e.g. `1e10000`), which `BigDecimal` expands into extremely larg…

📅 Published: March 23, 2026, 11:29 p.m. 🔄 Last Modified: March 25, 2026, 8:36 p.m.

8.1

CVSS3.1

CVE-2026-4021 - Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registr…

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email strin…

📅 Published: March 23, 2026, 11:25 p.m. 🔄 Last Modified: March 24, 2026, 6:43 p.m.

5.4

CVSS3.1

CVE-2026-4056 - User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Con…

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts`…

📅 Published: March 23, 2026, 11:25 p.m. 🔄 Last Modified: March 24, 2026, 10:29 a.m.

8.8

CVSS3.1

CVE-2026-3533 - JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload …

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authen…

📅 Published: March 23, 2026, 11:25 p.m. 🔄 Last Modified: March 24, 2026, 10:29 a.m.
Total resulsts: 340966
Page 140 of 34,097
« previous page » next page
Filters