8.3

CVSS3.1

CVE-2026-27802 - Vaultwarden: Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This issue has been patched in version 1.35.4.

πŸ“… Published: March 4, 2026, 9:34 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

6

CVSS4.0

CVE-2026-27801 - Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass t…

πŸ“… Published: March 4, 2026, 9:32 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

7.5

CVSS3.1

CVE-2026-28435 - Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized requ…

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or…

πŸ“… Published: March 4, 2026, 7:36 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

5.3

CVSS3.1

CVE-2026-28434 - cpp-httplib's default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and the application has not registered a custom exception handler via set_exception_handler(), the library catches the exception and writes its message di…

πŸ“… Published: March 4, 2026, 7:34 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

5.9

CVSS4.0

CVE-2026-28427 - OpenDeck affected by path traversal allows arbitrary file read

OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request path, an attacker can traverse outside the intended directo…

πŸ“… Published: March 4, 2026, 7:30 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

0.0

CVE-2026-3545 -

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 4, 2026, 7:24 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

0.0

CVE-2026-3544 -

Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 4, 2026, 7:24 p.m. πŸ”„ Last Modified: March 5, 2026, 4:56 a.m.

0.0

CVE-2026-3543 -

Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 4, 2026, 7:24 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

0.0

CVE-2026-3542 -

Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 4, 2026, 7:24 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.

0.0

CVE-2026-3541 -

Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 4, 2026, 7:24 p.m. πŸ”„ Last Modified: March 5, 2026, 9:05 a.m.
Total resulsts: 336101
Page 35 of 33,611
Β« previous page Β» next page
Filters