5.4

CVSS3.1

CVE-2026-22253 - Soft Serve is missing an authorization check in LFS lock deletion

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path proce…

πŸ“… Published: Jan. 8, 2026, 6:39 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

6.3

CVSS4.0

CVE-2026-21860 - Werkzeug safe_join() allows Windows special device names with compound extensions

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are special device names such as CON, AUX, etc that are implicitly present a…

πŸ“… Published: Jan. 8, 2026, 6:34 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

8.8

CVSS3.1

CVE-2026-22257 - Salvo is vulnerable to stored XSS in the list_html function by uploading files with malicious names

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to public files using this feature and anyone can upload…

πŸ“… Published: Jan. 8, 2026, 6:22 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

8.8

CVSS3.1

CVE-2026-22256 - Salvo is vulnerable to reflected XSS in the list_html function

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected XSS using the fact that request path is decoded a…

πŸ“… Published: Jan. 8, 2026, 6:21 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

5.8

CVSS4.0

CVE-2026-21896 - Kirby is missing permission checks in the content changes API

Kirby is an open-source content management system. From versions 5.0.0 to 5.2.1, Kirby is missing permission checks in the content changes API. This vulnerability affects all Kirby sites where user permissions are configured to prevent specific role(s) from performing write actions, specifically by…

πŸ“… Published: Jan. 8, 2026, 6:09 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

5.7

CVSS3.1

CVE-2025-68158 - Authlib: 1-click Account Takeover

Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid state (easily obtainable via an attacker-initiated a…

πŸ“… Published: Jan. 8, 2026, 5:58 p.m. πŸ”„ Last Modified: March 30, 2026, 12:20 p.m.

8.7

CVSS4.0

CVE-2026-22235 - OPEXUS eComplaint IDOR

OPEXUS eComplaint before version 9.0.45.0 allows an attacker to visit the the 'DocumentOpen.aspx' endpoint, iterate through predictable values of 'chargeNumber', and download any uploaded files.

πŸ“… Published: Jan. 8, 2026, 5:13 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

9.3

CVSS4.0

CVE-2026-22234 - OPEXUS eCasePortal unauthenticated IDOR

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

πŸ“… Published: Jan. 8, 2026, 5:12 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

4.8

CVSS4.0

CVE-2026-22233 - OPEXUS eCASE Audit Project Cost stored XSS

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.

πŸ“… Published: Jan. 8, 2026, 5:11 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

4.8

CVSS4.0

CVE-2026-22232 - OPEXUS eCASE Audit Project Setup stored XSS

OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript in the "A or SIC Number" field within the Project Setup functionality. The JavaScript is executed whenever another user views the project. Fixed in OPEXUS eCASE Audit 11.14.2.0.

πŸ“… Published: Jan. 8, 2026, 5:10 p.m. πŸ”„ Last Modified: April 18, 2026, 7:30 p.m.
Total resulsts: 348395
Page 2142 of 34,840
Β« previous page Β» next page
Filters