8.1

CVSS3.1

CVE-2026-28275 - Initiative Vulnerable to Improper Session Invalidation (JWT Remains Valid)

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access protected API endpoโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:56 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

8.7

CVSS3.1

CVE-2026-28274 - Initiative Vulnerable to Token Theft via Stored XSS in Document Uploads

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or `.htm` fโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:55 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

5.9

CVSS3.1

CVE-2026-28269 - Kiteworks Core has an OS Command Injection

Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Versโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

5.7

CVSS4.0

CVE-2026-28230 - In SteVe, any authenticated charger can terminate any other charger's active transaction (missing oโ€ฆ

SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transaction solely by transactionId (a sequential integer starting from 1) without verifying that the requesting charger matches โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:49 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.

6.5

CVSS3.1

CVE-2026-28226 - Phishing Club has Authenticated Blind SQL Injection in GetOrphaned Recipient Listing

Phishing Club is a phishing simulation and man-in-the-middle framework. Prior to version 1.30.2, an authenticated SQL injection vulnerability exists in the GetOrphaned recipient listing endpoint in versions prior to v1.30.2. The endpoint constructs a raw SQL query and concatenates the user-controllโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:43 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2026-28225 - Manyfold has IDOR in ModelFilesController

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.1, the `get_model` method in `ModelFilesController` (line 158-160) loads models using `Model.find_param(params[:model_id])` without `policy_scoโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:40 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4 p.m.

6.5

CVSS3.1

CVE-2026-28217 - IDOR in GraphQL userCollection Query Exposes Other Users' Private Collections

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, the `userCollection` GraphQL query accepts an arbitrary collection ID and returns the full collection data โ€” including title, type, and the serialized `data` field containing HTTP requests with headers and potentiallโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:15 p.m.

8.3

CVSS3.1

CVE-2026-28216 - hoppscotch has IDOR in updateUserEnvironment / deleteUserEnvironment

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver.ts:82-109`, `updateUserEnvironment` mutation uses `@UseGuards(GqlAuthGuard)` but is missing the `@Gโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:36 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4 p.m.

9.1

CVSS3.1

CVE-2026-28215 - hoppscotch Vulnerable to Unauthenticated Onboarding Config Takeover

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single HTTP POST request witโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:34 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3265 - go2ismail Free-CRM Security API improper authorization

A vulnerability was identified in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. This affects an unknown part of the file /api/Security/ of the component Security API. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploiโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 10:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.
Total resulsts: 349182
Page 1417 of 34,919
ยซ previous page ยป next page
Filters