5.8

CVSS3.1

CVE-2026-33081 - PinchTab has Blind SSRF via browser-side redirect bypass in /download URL validation

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below have a Blind SSRF vulnerability in the /download endpoint. The validateDownloadURL() function only checks the initial user-supplied URL, but the embedded Chromium browser can fol…

πŸ“… Published: March 20, 2026, 9:05 a.m. πŸ”„ Last Modified: March 20, 2026, 9:05 a.m.

7.3

CVSS3.1

CVE-2026-33080 - Filament: Unvalidated Range and Values summarizer values can be used for XSS

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database values without escaping HTML. If there is a lack of validation for the data in the…

πŸ“… Published: March 20, 2026, 8:58 a.m. πŸ”„ Last Modified: March 20, 2026, 8:58 a.m.

7.5

CVSS3.1

CVE-2026-32701 - Qwik has array method pollution in FormData processing, allowing type confusion and DoS

Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled properties to be written …

πŸ“… Published: March 20, 2026, 8:52 a.m. πŸ”„ Last Modified: March 20, 2026, 8:52 a.m.

8.1

CVSS3.1

CVE-2026-27625 - Stirling-PDF Zip Slip: Arbitrary File Write via Path Traversal in Markdown-to-PDF ZIP Extraction

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markdown/pdf endpoint extracts user-supplied ZIP entries without path checks. Any authenticated user can write files outside the intended temporary working…

πŸ“… Published: March 20, 2026, 8:44 a.m. πŸ”„ Last Modified: March 20, 2026, 8:44 a.m.

9.4

CVSS4.0

CVE-2026-33075 - FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-i…

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out c…

πŸ“… Published: March 20, 2026, 8:37 a.m. πŸ”„ Last Modified: March 20, 2026, 8:37 a.m.

8.2

CVSS3.1

CVE-2026-33072 - FileRise: Default Encryption Key Enables Token Forgery and Config Decryption

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_this_key) is used for all cryptographic operations β€” HMAC token generation, AES config encryption, and session tokens β€” allowing any unauthenticated atta…

πŸ“… Published: March 20, 2026, 8:31 a.m. πŸ”„ Last Modified: March 20, 2026, 8:31 a.m.

4.3

CVSS3.1

CVE-2026-33071 - FileRise: WebDAV upload path bypasses filename validation enforced by regular uploads

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml, .php5, .htaccess, and other server-side executable types, bypassing the filename validation enforced by the regular upload path. In non-def…

πŸ“… Published: March 20, 2026, 8:27 a.m. πŸ”„ Last Modified: March 20, 2026, 8:27 a.m.

4.4

CVSS3.1

CVE-2026-2432 - CM Custom Reports <= 1.2.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin …

The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

πŸ“… Published: March 20, 2026, 8:25 a.m. πŸ”„ Last Modified: March 20, 2026, 8:25 a.m.

5.3

CVSS3.1

CVE-2026-3550 - RockPress <= 1.0.17 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification v…

The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capability checks on multiple AJAX actions (rockpress_import, rockpress_import_status, rockpress_last_import, rockpress_reset_import, and rockpress_check_se…

πŸ“… Published: March 20, 2026, 8:25 a.m. πŸ”„ Last Modified: March 20, 2026, 8:25 a.m.

6.5

CVSS3.1

CVE-2026-2421 - ilGhera Carta Docente for WooCommerce <= 1.5.0 - Authenticated (Administrator+) Path Traversal to A…

The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the 'cert' parameter of the 'wccd-delete-certificate' AJAX action. This is due to insufficient file path validation before performing a file deletion. This …

πŸ“… Published: March 20, 2026, 8:25 a.m. πŸ”„ Last Modified: March 20, 2026, 8:25 a.m.
Total resulsts: 338950
Page 2 of 33,895
Β« previous page Β» next page
Filters