9.3

CVSS4.0

CVE-2026-22207 - OpenViking Missing root_api_key Allows Anonymous ROOT Access

OpenViking through version 0.1.18, prior to commitย 0251c70,ย contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 8:34 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 8:15 p.m.

8.3

CVSS4.0

CVE-2023-31364 -

Improper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtual machine (VM) to flood a host with writes, potentially causing a fatal machine check error resulting in denial of service.

๐Ÿ“… Published: Feb. 26, 2026, 8:33 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-22205 - SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive inโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 8:18 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

8.7

CVSS4.0

CVE-2026-22206 - SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 8:17 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

1.3

CVSS4.0

CVE-2026-27152 - DIscourse has DM communication-preference bypass when adding members

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddUsersToChannel` โ€” a user could add targets who have blocked/ignored/muted them to an existing DM channel, bypassing per-recipienโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 8 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

4.9

CVSS4.0

CVE-2026-27162 - DIscourse doesn't prevent whispers to leak in excerpts

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was checking topic access but then returning all posts regardless of type, including whispers that should only be visible to whisperers. Use `Post.secured(guardian)` to properly filtโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:58 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

1.3

CVSS4.0

CVE-2026-27151 - Discourse doesn't validate destination topic when moving posts

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` action only checked `can_move_posts?` on the source topic but never validated write permissions on the destination topic. This allowed TL4 users and category group moderators to moโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:57 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

1.3

CVSS4.0

CVE-2026-27150 - Discourse doesn't ensure guardian check when creating QueryGroupBookmark

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `QueryGroupBookmarkable` allows any logged-in user to create bookmarks for query groups they don't have access to, enabling metadatโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:55 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

4.9

CVSS4.0

CVE-2026-27149 - Discourse has SQL injection in PM tag filtering

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, SQL injection in PM tag filtering (`list_private_messages_tag`) allows bypassing tag filter conditions, potentially disclosing unauthorized private message metadata. Versions 2025.12.2, 2026.1.1, aโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 p.m.

6.9

CVSS4.0

CVE-2026-27021 - Discourse: Poll voters endpoint lacked post visibility checks

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the voters endpoint in the poll plugin lacked post visibility checks which allowed unauthorized access to voters details of polls in any post. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the iโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:50 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.
Total resulsts: 349182
Page 1420 of 34,919
ยซ previous page ยป next page
Filters