8.7

CVSS4.0

CVE-2026-25044 - Budibase: Command Injection in Bash Automation Step

Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided commands using execSync without proper sanitization or validation. User input is processed through processStringSync which allows template interpolation, potentially allowing arbit…

📅 Published: April 3, 2026, 3:38 p.m. 🔄 Last Modified: April 8, 2026, 9:19 p.m.

5.3

CVSS3.1

CVE-2026-25043 - Budibase: Unauthenticated Password Reset Endpoint Lacks Rate Limiting, Enabling Email Flooding

Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functionality due to the absence of rate limiting, CAPTCHA, or abuse prevention mechanisms on the “Forgot Password” endpoint. An unauthenticated attacker can re…

📅 Published: April 3, 2026, 3:35 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS4.0

CVE-2026-5470 - mixelpixx Google-Research-MCP Model Context Protocol content-extractor.service.ts extractContent se…

A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Model Context Protocol…

📅 Published: April 3, 2026, 3:30 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

7.1

CVSS4.0

CVE-2025-68153 - Juju: Resource poisoning

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, any authenticated user, machine or controller under a Juju contro…

📅 Published: April 3, 2026, 3:28 p.m. 🔄 Last Modified: April 7, 2026, 1:21 p.m.

6.9

CVSS4.0

CVE-2025-68152 - Juju: Read All Controller Logs From Compromised Workload

Juju is an open source application orchestration engine that enables any application operation on any infrastructure at any scale through special operators called ‘charms’. From versions 2.9 to before 2.9.56 and 3.6 to before 3.6.19, it is possible that a compromised workload machine under a Juju c…

📅 Published: April 3, 2026, 3:25 p.m. 🔄 Last Modified: April 7, 2026, 1:21 p.m.

8.2

CVSS4.0

CVE-2026-27124 - FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabi…

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvider OAuth integration, which allows authentication to a FastMCP MCP server via a FastMCP OAuthProxy using GitHub OAuth, it was discovered that the FastMCP OAuthProxy does not proper…

📅 Published: April 3, 2026, 3:22 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

6.7

CVSS3.1

CVE-2025-64340 - FastMCP has a Command Injection vulnerability - Gemini CLI

FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths use subprocess.run() w…

📅 Published: April 3, 2026, 3:16 p.m. 🔄 Last Modified: April 7, 2026, 1:21 p.m.

5.1

CVSS4.0

CVE-2026-5469 - Casdoor Webhook URL server-side request forgery

A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not re…

📅 Published: April 3, 2026, 2:30 p.m. 🔄 Last Modified: April 9, 2026, 12:14 a.m.

5.1

CVSS4.0

CVE-2026-5468 - Casdoor dangerouslySetInnerHTML cross site scripting

A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public …

📅 Published: April 3, 2026, 1:30 p.m. 🔄 Last Modified: April 9, 2026, 12:57 a.m.

4.3

CVSS3.1

CVE-2026-28736 - Focalboard IDOR in file content endpoint allows cross-user file access (unsupported product, no fix)

** UNSUPPORTED WHEN ASSIGNED ** Focalboard version 8.0 fails to validate file ownership when serving uploaded files. This allows an authenticated attacker who knows a victim's fileID to read the content of the file. NOTE: Focalboard as a standalone product is not maintained and no fix will be issue…

📅 Published: April 3, 2026, 1:25 p.m. 🔄 Last Modified: April 3, 2026, 9:16 p.m.
Total resulsts: 343968
Page 187 of 34,397
« previous page » next page
Filters