8.2

CVSS3.1

CVE-2026-4984 - Botpress - Credential Disclosure via Twilio Webhook Handler

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include the integration's Twilio credentials in the 'Authorization' he…

πŸ“… Published: March 27, 2026, 2:13 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

5.3

CVSS4.0

CVE-2026-4954 - mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection

A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit ha…

πŸ“… Published: March 27, 2026, 2:13 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

6.9

CVSS4.0

CVE-2026-4953 - mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible t…

πŸ“… Published: March 27, 2026, 2:13 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

9.4

CVSS4.0

CVE-2026-33758 - OpenBao has Reflected XSS in its OIDC authentication error message

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a fail…

πŸ“… Published: March 27, 2026, 2:12 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.5

CVSS3.1

CVE-2026-27880 - OpenFeature evaluation API reads input data with no bounds

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

πŸ“… Published: March 27, 2026, 2:12 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

9.6

CVSS3.1

CVE-2026-33757 - OpenBao lacks user confirmation for OIDC direct callback mode

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote phis…

πŸ“… Published: March 27, 2026, 2:10 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.3

CVSS4.0

CVE-2024-11604 - Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 bit allows authenticated local users to obtain sensitive information via access to log files. This issue affects IDM SCIM Driver: 1.0.0.0000 through 1…

πŸ“… Published: March 27, 2026, 2:08 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

8.8

CVSS3.1

CVE-2026-33755 - Authenticated SQL Injection in Contact/query addressBookIds filter

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows any authenticated user with basic addressbook access to extract arbitrary data…

πŸ“… Published: March 27, 2026, 2:08 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

6.5

CVSS3.1

CVE-2026-33750 - brace-expansion: Zero-step sequence causes process hang and memory exhaustion

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence generation loop to run indefinitely, making the process hang for seconds a…

πŸ“… Published: March 27, 2026, 2:04 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

6.5

CVSS3.1

CVE-2026-27877 - Public dashboards discloses all direct mode datasources

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve yo…

πŸ“… Published: March 27, 2026, 2:02 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.
Total resulsts: 341122
Page 30 of 34,113
Β« previous page Β» next page
Filters