6.4

CVSS3.1

CVE-2026-28682 - Gokapi: Data Leak in Upload Status Stream

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any authenticated listener and includes file_id values that are not scoped to the requesting u…

📅 Published: March 6, 2026, 4:43 a.m. 🔄 Last Modified: March 6, 2026, 4:43 a.m.

8.1

CVSS3.1

CVE-2026-28681 - IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email li…

Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request…

📅 Published: March 6, 2026, 4:35 a.m. 🔄 Last Modified: March 6, 2026, 4:35 a.m.

8.6

CVSS3.1

CVE-2026-28679 - HomeGallery: Path Traversal (Arbitrary File Read)

Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0, when a user requests a download, the application does not verify whether the requested file is located within the media source directory, which can result in sensitive system fil…

📅 Published: March 6, 2026, 4:32 a.m. 🔄 Last Modified: March 6, 2026, 4:32 a.m.

9.3

CVSS4.0

CVE-2026-28785 - Ghostfolio: Time-Based Blind SQL Injection in Manual Asset Import

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the databa…

📅 Published: March 6, 2026, 4:27 a.m. 🔄 Last Modified: March 6, 2026, 4:27 a.m.

9.3

CVSS3.1

CVE-2026-28680 - Ghostfolio: Full-Read SSRF in Manual Asset Import

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in vers…

📅 Published: March 6, 2026, 4:26 a.m. 🔄 Last Modified: March 6, 2026, 4:26 a.m.

8.2

CVSS3.1

CVE-2026-28677 - OpenSift: Insufficient URL destination restrictions in ingest flow could enable SSRF-style internal…

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, the URL ingest pipeline accepted user-controlled remote URLs with incomplete destination restrictions. Although private/local host checks existed, missing restrictio…

📅 Published: March 6, 2026, 4:23 a.m. 🔄 Last Modified: March 6, 2026, 4:23 a.m.

8.8

CVSS3.1

CVE-2026-28676 - OpenSift: Insufficient path containment checks in storage helpers could allow path traversal-style …

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, multiple storage helpers used path construction patterns that did not uniformly enforce base-directory containment. This created path-injection risk in file read/wri…

📅 Published: March 6, 2026, 4:23 a.m. 🔄 Last Modified: March 6, 2026, 4:23 a.m.

5.3

CVSS3.1

CVE-2026-28675 - OpenSift: Sensitive implementation details exposed via raw exception messages and token-returning e…

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version 1.6.3-alpha, some endpoints returned raw exception strings to clients. Additionally, login token material was exposed in UI/rendered responses and token rotation output. This iss…

📅 Published: March 6, 2026, 4:22 a.m. 🔄 Last Modified: March 6, 2026, 4:22 a.m.

6.3

CVSS3.1

CVE-2026-28509 - LangBot has a Cross Site Scripting(XSS) Vulnerability

LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied raw HTML using rehypeRaw, which can lead to a cross-site scripting (XSS) vulnerability. This issue has been patched in version 4.8.7.

📅 Published: March 6, 2026, 4:16 a.m. 🔄 Last Modified: March 6, 2026, 4:16 a.m.

9.2

CVSS4.0

CVE-2026-28508 - Idno: Unauthenticated SSRF via URL Unfurl Endpoint

Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker. Combined with the absence of a login requirement on the endpoint …

📅 Published: March 6, 2026, 4:13 a.m. 🔄 Last Modified: March 6, 2026, 4:13 a.m.
Total resulsts: 336508
Page 20 of 33,651
« previous page » next page
Filters