9.8

CVSS3.1

CVE-2026-28213 - EverShop Vulnerable to Arbitrary Customer Account Takeover via Exposure of Password Reset Token in …

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Version 2.1…

πŸ“… Published: Feb. 26, 2026, 10:31 p.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

7.8

CVSS3.1

CVE-2026-28211 - Arbitrary code execution in log reader via untrusted log file

The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A maliciously crafted log file can lead to arbitrary code execution when a user reads it with log read…

πŸ“… Published: Feb. 26, 2026, 10:29 p.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

5.9

CVSS3.1

CVE-2026-28208 - Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on L…

Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix…

πŸ“… Published: Feb. 26, 2026, 10:20 p.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

6.6

CVSS3.1

CVE-2026-28207 - Zen-C Vulnerable to Command Injection via Malicious Output Filename

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shell commands by providing a specially crafted output filename via the `-o` comman…

πŸ“… Published: Feb. 26, 2026, 10:17 p.m. πŸ”„ Last Modified: May 1, 2026, 2:38 p.m.

5.7

CVSS4.0

CVE-2026-27638 - ActualBudget missing authorization in sync endpoints allows cross-user budget file access in multi-…

Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenticated user can read, modify, and overwrite any other user's …

πŸ“… Published: Feb. 26, 2026, 10:14 p.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

4.3

CVSS3.1

CVE-2026-27839 - wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` β€” a raw ORM call that bypasses the user-scoped queryset. Any authenticated user can read another user's private nutr…

πŸ“… Published: Feb. 26, 2026, 10:07 p.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

3.1

CVSS3.1

CVE-2026-27838 - wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` β€” no user ID is included. When a victim has previously accessed their routine via th…

πŸ“… Published: Feb. 26, 2026, 10:04 p.m. πŸ”„ Last Modified: April 16, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3264 - go2ismail Free-CRM Administrative redirect

A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administrative Interface. Executing a manipulation can lead to execution after redirect. The attack can be executed remotely. Th…

πŸ“… Published: Feb. 26, 2026, 10:02 p.m. πŸ”„ Last Modified: April 18, 2026, 10:30 a.m.

4.3

CVSS3.1

CVE-2026-27835 - wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data because their `get_queryset()` calls `.all()` instead of filtering by the authenticated user. Any regis…

πŸ“… Published: Feb. 26, 2026, 10 p.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.

4.3

CVSS3.1

CVE-2026-27457 - Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user (or anonymous users…

πŸ“… Published: Feb. 26, 2026, 9:56 p.m. πŸ”„ Last Modified: April 17, 2026, 2:15 p.m.
Total resulsts: 349182
Page 1418 of 34,919
Β« previous page Β» next page
Filters