0.0

CVE-2025-13476 - Rakuten Viber uses broken or risky cryptographic Algorithm

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (C…

📅 Published: March 5, 2026, 4:53 p.m. 🔄 Last Modified: March 6, 2026, 10:36 a.m.

9.8

CVSS3.1

CVE-2026-27944 - Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to down…

📅 Published: March 5, 2026, 4:28 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

9.1

CVSS3.1

CVE-2026-24457 -

An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved.

📅 Published: March 5, 2026, 4:27 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

4.3

CVSS3.1

CVE-2026-27723 - OpenProject: Insufficient access control leads to create Wiki objects belongs unpermitted projects

OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker can create wiki pages belonging to unpermitted projects through an improperly authenticated request. This issue has been patched in versions 17.0.5 and 17.1.2.

📅 Published: March 5, 2026, 4:26 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

5

CVSS3.1

CVE-2026-27023 - Twenty: SSRF protection bypass via HTTP redirect following in secure HTTP client

Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request URLs at the request level but did not validate redirect targets. An authenticated user who could control outbound request URLs (e.g., webhook endpoints, image URLs) could bypass pri…

📅 Published: March 5, 2026, 4:23 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

7.5

CVSS3.1

CVE-2026-29054 - Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for e…

Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik managing the Connection header with X-Forwarded headers. When Traefik processes HTTP/1.1 requests, the protection put in place to prevent…

📅 Published: March 5, 2026, 4:18 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

7.5

CVSS3.1

CVE-2026-26999 - Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowl…

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before …

📅 Published: March 5, 2026, 4:15 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

4.4

CVSS3.1

CVE-2026-26998 - Traefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS)

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is rea…

📅 Published: March 5, 2026, 4:15 p.m. 🔄 Last Modified: March 5, 2026, 7:38 p.m.

8.2

CVSS4.0

CVE-2026-30785 - RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Pol…

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Password security module, config encryption, machine…

📅 Published: March 5, 2026, 4:04 p.m. 🔄 Last Modified: March 6, 2026, 10:32 a.m.

8.8

CVSS4.0

CVE-2026-30784 - RustDesk hbbs/hbbr Servers Broker Connections Without Any Authorization Check

Missing Authorization, Missing Authentication for Critical Function vulnerability in rustdesk-server RustDesk Server rustdesk-server, rustdesk-server-pro on hbbs/hbbr on all server platforms (Rendezvous server (hbbs), relay server (hbbr) modules) allows Privilege Abuse. This vulnerability is associ…

📅 Published: March 5, 2026, 3:58 p.m. 🔄 Last Modified: March 6, 2026, 10:29 a.m.
Total resulsts: 336474
Page 33 of 33,648
« previous page » next page
Filters