4.4

CVSS3.1

CVE-2026-2289 - Taskbuilder <= 5.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails…

The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a…

📅 Published: March 4, 2026, 1:21 a.m. 🔄 Last Modified: March 4, 2026, 1:21 a.m.

7.2

CVSS3.1

CVE-2026-1945 - WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_e…

The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje…

📅 Published: March 4, 2026, 1:21 a.m. 🔄 Last Modified: March 4, 2026, 1:21 a.m.

10

CVSS3.1

CVE-2026-28289 - FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Co…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a maliciou…

📅 Published: March 3, 2026, 10:59 p.m. 🔄 Last Modified: March 3, 2026, 10:59 p.m.

9.2

CVSS4.0

CVE-2026-27971 - Qwik affected by unauthenticated RCE via server$ Deserialization

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where re…

📅 Published: March 3, 2026, 10:55 p.m. 🔄 Last Modified: March 3, 2026, 10:55 p.m.

7.5

CVSS3.1

CVE-2026-27932 - joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library…

📅 Published: March 3, 2026, 10:48 p.m. 🔄 Last Modified: March 3, 2026, 10:48 p.m.

8.6

CVSS4.0

CVE-2026-27905 - BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path…

📅 Published: March 3, 2026, 10:45 p.m. 🔄 Last Modified: March 3, 2026, 10:45 p.m.

8.4

CVSS4.0

CVE-2026-27622 - OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across man…

📅 Published: March 3, 2026, 10:42 p.m. 🔄 Last Modified: March 3, 2026, 10:42 p.m.

8.2

CVSS4.0

CVE-2026-27601 - Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untr…

📅 Published: March 3, 2026, 10:38 p.m. 🔄 Last Modified: March 3, 2026, 10:38 p.m.

9.1

CVSS3.1

CVE-2026-26279 - Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adm…

📅 Published: March 3, 2026, 10:31 p.m. 🔄 Last Modified: March 3, 2026, 10:31 p.m.

8.3

CVSS4.0

CVE-2026-3266 - Improper access control vulnerability has been discovered in OpenText™ Filr.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

📅 Published: March 3, 2026, 10:28 p.m. 🔄 Last Modified: March 3, 2026, 10:28 p.m.
Total resulsts: 335584
Page 2 of 33,559
« previous page » next page
Filters