9.8

CVSS3.1

CVE-2026-2331 - CVE-2026-2331

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without…

📅 Published: March 6, 2026, 7:56 a.m. 🔄 Last Modified: March 6, 2026, 7:56 a.m.

9.4

CVSS3.1

CVE-2026-2330 - CVE-2026-2330

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could pla…

📅 Published: March 6, 2026, 7:54 a.m. 🔄 Last Modified: March 6, 2026, 7:54 a.m.

7.5

CVSS3.1

CVE-2026-29074 - SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion…

📅 Published: March 6, 2026, 7:23 a.m. 🔄 Last Modified: March 6, 2026, 7:23 a.m.

6.1

CVSS3.1

CVE-2026-2830 - WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath'

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible…

📅 Published: March 6, 2026, 7:22 a.m. 🔄 Last Modified: March 6, 2026, 7:22 a.m.

9.3

CVSS3.1

CVE-2026-29183 - SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrar…

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when type=8, attacker-controlled content is embedded into SVG output without escaping. Because the endpoint…

📅 Published: March 6, 2026, 7:18 a.m. 🔄 Last Modified: March 6, 2026, 7:18 a.m.

5.7

CVSS4.0

CVE-2026-29073 - SiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database access

SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directly, but it only checks basic auth, not admin rights, any logged-in user, even readers, can run any sql query on the database. This issue has been patched in version 3.6.0.

📅 Published: March 6, 2026, 7:18 a.m. 🔄 Last Modified: March 6, 2026, 7:18 a.m.

8.7

CVSS4.0

CVE-2026-29062 - jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Res…

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 to before version 3.1.0, the UTF8DataInputJsonParser, which is used when parsing from a java.io.DataInput source, bypasses the maxNestingDepth constrai…

📅 Published: March 6, 2026, 7:14 a.m. 🔄 Last Modified: March 6, 2026, 2:55 p.m.

6.9

CVSS4.0

CVE-2026-29059 - Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename paramet…

📅 Published: March 6, 2026, 7:11 a.m. 🔄 Last Modified: March 6, 2026, 7:11 a.m.

9.8

CVSS3.1

CVE-2026-29058 - AVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration se…

📅 Published: March 6, 2026, 7:08 a.m. 🔄 Last Modified: March 6, 2026, 7:08 a.m.

4.3

CVSS3.1

CVE-2026-29049 - melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI

melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cache downloads URIs from build configs via io.Copy without any size limit or HTTP client timeout (pkg/renovate/cache/cache.go). An attacker-controlled URI in a melange config can cau…

📅 Published: March 6, 2026, 7:03 a.m. 🔄 Last Modified: March 6, 2026, 7:03 a.m.
Total resulsts: 336516
Page 17 of 33,652
« previous page » next page
Filters