5.1

CVSS4.0

CVE-2026-4346 - Cleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Lin…

The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attacker with physical access and the ability to connect to the ser…

📅 Published: March 26, 2026, 9:16 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

9.8

CVSS3.1

CVE-2026-33670 - SiYuan has directory traversal within its publishing service

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

📅 Published: March 26, 2026, 9:15 p.m. 🔄 Last Modified: March 26, 2026, 10:16 p.m.

9.8

CVSS3.1

CVE-2026-33669 - SiYuan has Arbitrary Document Reading within the Publishing Service

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

📅 Published: March 26, 2026, 9:14 p.m. 🔄 Last Modified: March 27, 2026, 8:26 p.m.

6.9

CVSS4.0

CVE-2026-1556 - Information disclosure via file URI overwrite in File (Field) Paths

Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenticated users to disclose other users’ private files via filename‑collision uploads. This can cause hook_node_insert() consumers (for example, email att…

📅 Published: March 26, 2026, 9:14 p.m. 🔄 Last Modified: March 27, 2026, 7:39 p.m.

7.3

CVSS3.1

CVE-2026-33664 - Kestra Vulnerable to Stored Cross-Site Scripting via Flow YAML Fields

Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — description, inputs[].displayName, inputs[].description — through the Markdown.vue component instantiated with html: true. The resulting HTML is injected…

📅 Published: March 26, 2026, 9:13 p.m. 🔄 Last Modified: March 26, 2026, 10:16 p.m.

8.7

CVSS4.0

CVE-2026-3650 - Grassroots DICOM Missing release of memory after effective lifetime

A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously craf…

📅 Published: March 26, 2026, 9:10 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

5.3

CVSS4.0

CVE-2026-4898 - code-projects Online Food Ordering System contact.php cross site scripting

A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The explo…

📅 Published: March 26, 2026, 9:08 p.m. 🔄 Last Modified: March 27, 2026, 8:26 p.m.

8.6

CVSS3.1

CVE-2026-33661 - WeChat Pay callback signature verification bypassed when Host header is localhost

Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can expl…

📅 Published: March 26, 2026, 9:05 p.m. 🔄 Last Modified: March 27, 2026, 8 p.m.

2.3

CVSS4.0

CVE-2026-33658 - Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU…

📅 Published: March 26, 2026, 9:03 p.m. 🔄 Last Modified: March 26, 2026, 10:16 p.m.

4.6

CVSS3.1

CVE-2026-33653 - Uploady Vulnerable to Stored Cross-Site Scripting (XSS)

Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. An attacker can upload a file with a malicious filename containing JavaScri…

📅 Published: March 26, 2026, 9 p.m. 🔄 Last Modified: March 27, 2026, 8:16 p.m.
Total resulsts: 341042
Page 35 of 34,105
« previous page » next page
Filters