7.7

CVSS3.1

CVE-2026-21887 - OpenCTI has a Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-supplied URLs without validation and uses the Axios HTTP client with its default configuration (allowAbsoluteUrls: true). …

πŸ“… Published: March 12, 2026, 5 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

6.2

CVSS3.1

CVE-2026-29066 - Arbitrary File Read via Disabled Vite Filesystem Restriction in TinaCMS CLI

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.strict: false, which disables Vite's built-in filesystem access restriction. This allows any unauthenticated attacker who can reach the dev server to read arbitrary files on the h…

πŸ“… Published: March 12, 2026, 4:57 p.m. πŸ”„ Last Modified: March 13, 2026, 7:57 p.m.

7.4

CVSS3.1

CVE-2026-28791 - Path Traversal in Media Upload Handle in Tina

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path stays within the intend…

πŸ“… Published: March 12, 2026, 4:55 p.m. πŸ”„ Last Modified: March 13, 2026, 7:55 p.m.

8.4

CVSS3.1

CVE-2026-28793 - Path Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMS

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the …

πŸ“… Published: March 12, 2026, 4:50 p.m. πŸ”„ Last Modified: March 13, 2026, 7:58 p.m.

9.7

CVSS3.1

CVE-2026-28792 - Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate …

πŸ“… Published: March 12, 2026, 4:48 p.m. πŸ”„ Last Modified: March 13, 2026, 7:54 p.m.

7.5

CVSS3.1

CVE-2026-28356 - ReDoS in multipart 1.3.0 - `parse_options_header()`

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or mult…

πŸ“… Published: March 12, 2026, 4:45 p.m. πŸ”„ Last Modified: March 13, 2026, 4:29 p.m.

7.8

CVSS3.1

CVE-2026-27940 - llama.cpp has a Heap Buffer Overflow via Integer Overflow in `mem_size` Calculation β€” Bypass of CVE…

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past the buffer boundary. T…

πŸ“… Published: March 12, 2026, 4:39 p.m. πŸ”„ Last Modified: March 14, 2026, 3:55 a.m.

8.1

CVSS3.1

CVE-2026-25529 - Postal has HTML injection / XSS in message view

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for unescaped data to be added is via the API's "send/raw" method. This could allow arbitrary HTML to be inject…

πŸ“… Published: March 12, 2026, 4:35 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

6.3

CVSS3.1

CVE-2026-24125 - Path Traversal in @tinacms/graphql

Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative file paths (relativePath, newRelativePath) via GraphQL mutations. Under certain conditions, these paths are combined with the collection path using path.…

πŸ“… Published: March 12, 2026, 4:31 p.m. πŸ”„ Last Modified: March 13, 2026, 7:22 p.m.

10

CVSS3.1

CVE-2026-21708 -

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

πŸ“… Published: March 12, 2026, 4:26 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.
Total resulsts: 337973
Page 35 of 33,798
Β« previous page Β» next page
Filters