9.3

CVSS3.1

CVE-2026-27614 - Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments ret…

πŸ“… Published: Feb. 25, 2026, 2:31 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

7.1

CVSS4.0

CVE-2026-27611 - FileBrowser Quantum: Password Protection Not Enforced on Shared File Links

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in …

πŸ“… Published: Feb. 25, 2026, 2:24 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

9.9

CVSS4.0

CVE-2026-27595 - Parse Dashboard has incomplete authentication on AI Agent endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, allow unauthenticated remote attackers to perform arbitrary rea…

πŸ“… Published: Feb. 25, 2026, 2:21 a.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

7

CVSS4.0

CVE-2026-27610 - Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-only master key when resolving function-typed keys. Under specific timing conditions, a read-only use…

πŸ“… Published: Feb. 25, 2026, 2:19 a.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

8.3

CVSS4.0

CVE-2026-27609 - Parse Dashboard Missing CSRF Protection on Agent Endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) lacks CSRF protection. An attacker can craft a malicious page that, when visited by an authenticated dashboard user, subm…

πŸ“… Published: Feb. 25, 2026, 2:18 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

9.3

CVSS4.0

CVE-2026-27608 - Parse Dashboard Missing Authorization on Agent Endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint by …

πŸ“… Published: Feb. 25, 2026, 2:16 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

9.1

CVSS3.1

CVE-2026-27822 - Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF preview logic, an a…

πŸ“… Published: Feb. 25, 2026, 2:11 a.m. πŸ”„ Last Modified: April 18, 2026, 7:45 p.m.

8.1

CVSS3.1

CVE-2026-27607 - RustFS's Missing Post Policy Validation leads to Arbitrary Object Write

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enabl…

πŸ“… Published: Feb. 25, 2026, 2:10 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

8.8

CVSS4.0

CVE-2026-27606 - Rollup 4 has Arbitrary File Write via Path Traversal

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker t…

πŸ“… Published: Feb. 25, 2026, 2:08 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

4.5

CVSS3.1

CVE-2026-25135 - OpenEMR's location resource for Group.$export operation returns entire patient/user population cont…

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 have an information disclosure vulnerability that leaks the entire contact information for all users, organizations, and patients in the system to anyone who has the syst…

πŸ“… Published: Feb. 25, 2026, 2:02 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.
Total resulsts: 349182
Page 1453 of 34,919
Β« previous page Β» next page
Filters