4.5

CVSS4.0

CVE-2026-21883 - Bokeh server applications have Incomplete Origin Validation in WebSockets

Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can register a domain like dashboard.corp.attacker.com (or use a subdomain if applicable) and lure a victim to visit it. The …

πŸ“… Published: Jan. 8, 2026, 1:20 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

9.1

CVSS3.1

CVE-2026-21881 - Kanboard is Vulnerable to Reverse Proxy Authentication Bypass

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a …

πŸ“… Published: Jan. 8, 2026, 1:08 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

5.3

CVSS3.1

CVE-2026-21880 - Kanboard LDAP Injection Vulnerability can Lead to User Enumeration and Information Disclosure

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumera…

πŸ“… Published: Jan. 8, 2026, 12:59 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

4.7

CVSS3.1

CVE-2026-21879 - Kanboard vulnerable to Open Redirect via protocol-relative URLs

Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs such as //evil.com, attackers can bypass the filt…

πŸ“… Published: Jan. 8, 2026, 12:51 a.m. πŸ”„ Last Modified: April 18, 2026, 5 p.m.

10

CVSS3.1

CVE-2026-21877 - n8n is vulnerable to Remote Code Execution via Arbitrary File Write

n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Cloud instances. This issue is fixed in version 1.12…

πŸ“… Published: Jan. 8, 2026, 12:39 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

7.5

CVSS3.1

CVE-2026-21868 - Flag Forge has ReDoS Vulnerability in User Profile Lookup API

Flag Forge is a Capture The Flag (CTF) platform. Versions 2.3.2 and below have a Regular Expression Denial of Service (ReDoS) vulnerability in the user profile API endpoint (/api/user/[username]). The application constructs a regular expression dynamically using unescaped user input (the username p…

πŸ“… Published: Jan. 8, 2026, 12:26 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

7.8

CVSS3.1

CVE-2026-22035 - Greenshot Vulnerable to OS Command Injection via ExternalCommand Plugin

Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments method in ExternalCommandDestination.cs:269 uses string.Format() to insert user-controlled filenames directly into she…

πŸ“… Published: Jan. 8, 2026, 12:10 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

7.5

CVSS3.1

CVE-2025-65518 - plesk: Plesk Obsidian: Denial of Service via crafted request to get_password.php

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service u…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 1:08 a.m.

8.1

CVSS3.1

CVE-2025-67089 -

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands w…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:26 p.m.

9.4

CVSS3.1

CVE-2025-68717 -

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's …

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 4:35 p.m.
Total resulsts: 349182
Page 2236 of 34,919
Β« previous page Β» next page
Filters