8.5

CVSS3.1

CVE-2026-31943 - LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized form, allowing any authenticated user to bypass SSRF protection and make the server issue HTTP reque…

πŸ“… Published: March 27, 2026, 7:21 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.

6.6

CVSS4.0

CVE-2026-34391 - Fleet Vulnerable to Windows MDM cross-device command disclosure

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secrets, …

πŸ“… Published: March 27, 2026, 7:19 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.

4.9

CVSS4.0

CVE-2026-34389 - Fleet's user account creation via invite does not enforce invited email address

Fleet is open source device management software. Prior to 4.81.0, Fleet contained an issue in the user invitation flow where the email address provided during invite acceptance was not validated against the email address associated with the invite. An attacker who obtained a valid invite token coul…

πŸ“… Published: March 27, 2026, 7:18 p.m. πŸ”„ Last Modified: March 29, 2026, 8:30 p.m.

4.8

CVSS4.0

CVE-2026-4972 - code-projects Online Reviewer System btn_functions.php cross site scripting

A security vulnerability has been detected in code-projects Online Reviewer System up to 1.0. Affected is an unknown function of the file /system/system/students/assessments/databank/btn_functions.php. Such manipulation of the argument Description leads to cross site scripting. The attack may be pe…

πŸ“… Published: March 27, 2026, 7:15 p.m. πŸ”„ Last Modified: March 29, 2026, 8:30 p.m.

5.3

CVSS4.0

CVE-2026-4971 - SourceCodester Note Taking App cross-site request forgery

A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

πŸ“… Published: March 27, 2026, 7:15 p.m. πŸ”„ Last Modified: March 29, 2026, 8:30 p.m.

6.6

CVSS4.0

CVE-2026-34388 - Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint

Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The server terminates immediately, disrupting all conn…

πŸ“… Published: March 27, 2026, 7:13 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.

5.7

CVSS4.0

CVE-2026-34387 - Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an attacker to achieve arbitrary code execution as root (macOS/Linux) or SYSTEM (Windows) on managed hosts when an uninstall is triggered for a crafted s…

πŸ“… Published: March 27, 2026, 6:31 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.

6.3

CVSS4.0

CVE-2026-34386 - Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin

Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap package configuration allows an authenticated user with Team Admin or Global Admin privileges to modify arbitrary team configurations, exfiltrate sensitive data from the Fleet da…

πŸ“… Published: March 27, 2026, 6:30 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.

6.2

CVSS4.0

CVE-2026-34385 - Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database

Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's Apple MDM profile delivery pipeline could allow an attacker with a valid MDM enrollment certificate to exfiltrate or modify the contents of the Fleet database, including user cred…

πŸ“… Published: March 27, 2026, 6:29 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.

4.9

CVSS4.0

CVE-2026-29180 - Fleet's team maintainer can transfer hosts from any team via missing source team authorization

Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. Once transferred, the attacker gains full control o…

πŸ“… Published: March 27, 2026, 6:27 p.m. πŸ”„ Last Modified: March 30, 2026, 7 a.m.
Total resulsts: 341106
Page 22 of 34,111
Β« previous page Β» next page
Filters