8.7

CVSS4.0

CVE-2026-4974 - Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to launch the attack r…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

5.1

CVSS4.0

CVE-2026-4973 - SourceCodester Online Quiz System add-question.php cross site scripting

A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument quiz_question results in cross site scripting. It is possible to initiate the atta…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

4.8

CVSS3.1

CVE-2026-33869 - Mastodon has a denial of service for quote authorization

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vuln…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2026-33868 - Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can craft a specially enc…

📅 Published: March 27, 2026, 7:50 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

8.9

CVSS4.0

CVE-2026-33765 - Pi-hole Web Interface has a Command Injection Vulnerability

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] paramete…

📅 Published: March 27, 2026, 7:46 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

5.7

CVSS3.1

CVE-2026-33739 - FOG has Stored XSS in Multiple Management Pages

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter san…

📅 Published: March 27, 2026, 7:45 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

8.9

CVSS4.0

CVE-2026-33654 - Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling

nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channels/email.py`), allowing a remote, unauthenticated attacker to execute arbitrary LLM instructions (and subsequently, system tools) with…

📅 Published: March 27, 2026, 7:43 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

9.7

CVSS3.1

CVE-2026-34205 - Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mo…

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuratio…

📅 Published: March 27, 2026, 7:41 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

5.4

CVSS3.1

CVE-2026-34475 - Varnish Cache URL Handling Leading to Cache Poisoning and Authentication Bypass

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

📅 Published: March 27, 2026, 7:40 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

7.3

CVSS4.0

CVE-2026-33045 - Home Assistant has stored XSS in history-graphs

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, simila…

📅 Published: March 27, 2026, 7:39 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.
Total resulsts: 341080
Page 18 of 34,108
« previous page » next page
Filters