4.6

CVSS3.1

CVE-2026-1628 - Mattermost allows external websites to open within the app, exposing preload functionality to non-tโ€ฆ

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Matterโ€ฆ

๐Ÿ“… Published: March 2, 2026, 1:24 p.m. ๐Ÿ”„ Last Modified: March 2, 2026, 2:16 p.m.

9.3

CVSS4.0

CVE-2026-3432 - Sim Studio AI - Unauthenticated OAuth Token Theft

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying theโ€ฆ

๐Ÿ“… Published: March 2, 2026, 1:01 p.m. ๐Ÿ”„ Last Modified: March 2, 2026, 1:32 p.m.

9.8

CVSS3.1

CVE-2026-3431 - Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reโ€ฆ

๐Ÿ“… Published: March 2, 2026, 1 p.m. ๐Ÿ”„ Last Modified: March 2, 2026, 1:33 p.m.

9.3

CVSS4.0

CVE-2025-14532 - Remote Code Execution via Unrestricted File Upload in DobryCMS

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

๐Ÿ“… Published: March 2, 2026, 12:49 p.m. ๐Ÿ”„ Last Modified: March 2, 2026, 1:34 p.m.

9.3

CVSS4.0

CVE-2025-12462 - Blind SQL Injection in DobryCMS

A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path resulting in Blind SQL Injection. This issue was fixed in versions above 8.0.

๐Ÿ“… Published: March 2, 2026, 12:49 p.m. ๐Ÿ”„ Last Modified: March 2, 2026, 1:35 p.m.

5.3

CVSS4.0

CVE-2025-58406 - Lack of HTTP Response Headers

The CGM CLININET application respond without essential security HTTP headers, exposing users to clientโ€‘side attacks such as clickjacking, MIME sniffing, unsafe caching, weak crossโ€‘origin isolation, and missing transport security controls.

๐Ÿ“… Published: March 2, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 8:29 p.m.

5.3

CVSS4.0

CVE-2025-58405 - Lack of protection mechanisms against Clickjacking attacks

The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frameโ€‘busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performโ€ฆ

๐Ÿ“… Published: March 2, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 8:29 p.m.

7.1

CVSS4.0

CVE-2025-58402 - Insecure Direct Object Reference Message ID

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

๐Ÿ“… Published: March 2, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 8:29 p.m.

6.9

CVSS4.0

CVE-2025-30062 - SQL injection in CheckUnitCodeAndKey.pl

In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.

๐Ÿ“… Published: March 2, 2026, 11:16 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 8:29 p.m.

9.4

CVSS4.0

CVE-2025-30044 - RCE on uhcapache user permissions

In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl", the parameters are not sufficiently normalized, which enables code injection.

๐Ÿ“… Published: March 2, 2026, 11:15 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 1:20 p.m.
Total resulsts: 335443
Page 15 of 33,545
ยซ previous page ยป next page
Filters