4.8

CVSS4.0

CVE-2026-4899 - code-projects Online Food Ordering System food.php cross site scripting

A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argument cuisines results in cross site scripting. It is possible to launch the attack remotely. The exploโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:56 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:31 a.m.

8.8

CVSS3.1

CVE-2026-33686 - Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtil

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, allowing path separators to be passed into the storage layer. In `src/Utils/FileUtโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:54 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 1:59 p.m.

8.8

CVSS3.1

CVE-2026-33687 - Sharp has Unrestricted File Upload via Client-Controlled Validation Rules

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-controโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:47 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:28 p.m.

4.7

CVSS3.1

CVE-2026-33682 - Streamlit on Windows has Unauthenticated SSRF Vulnerability (NTLM Credential Exposure)

Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesysโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:45 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8 p.m.

2

CVSS3.1

CVE-2026-33674 - PrestaShop: Improper Use of Validation Framework

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.

๐Ÿ“… Published: March 26, 2026, 9:42 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 10:16 p.m.

7.7

CVSS3.1

CVE-2026-33673 - PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, โ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:41 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:27 p.m.

7.5

CVSS3.1

CVE-2026-28377 - S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern)

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

๐Ÿ“… Published: March 26, 2026, 9:39 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:26 p.m.

5.3

CVSS3.1

CVE-2026-33672 - Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:construโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:39 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 3:47 p.m.

7.5

CVSS3.1

CVE-2026-33671 - Picomatch has a ReDoS vulnerability via extglob quantifiers

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlaโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:20 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8 p.m.

5.3

CVSS4.0

CVE-2026-0748 - Access bypass in Drupal 7 i18n_node translation UI

In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls aโ€ฆ

๐Ÿ“… Published: March 26, 2026, 9:17 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 3:16 p.m.
Total resulsts: 341062
Page 36 of 34,107
ยซ previous page ยป next page
Filters