6.9

CVSS4.0

CVE-2026-3849 - Buffer Overflow in HPKE via Oversized ECH Config

Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on the client side, leading to potential remote execution and client pro…

πŸ“… Published: March 19, 2026, 8:29 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

4.1

CVSS3.1

CVE-2026-27166 - Discourse vulnerable to HTML injection via prohibited iframe URLs

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page. This issue has been fixed in versions 2026.3.0-l…

πŸ“… Published: March 19, 2026, 8:29 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

6.5

CVSS3.1

CVE-2026-33304 - OpenEMR has Authorization Bypass in Dated Reminders Log

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including associated patient name…

πŸ“… Published: March 19, 2026, 8:27 p.m. πŸ”„ Last Modified: March 20, 2026, 7:27 p.m.

5.4

CVSS3.1

CVE-2026-33303 - OpenEMR Vulnerable to Stored XSS via Unescaped portal_login_username in Credential Print View

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped `portal_login_username` in the portal credential print view. A patient portal user can set their login…

πŸ“… Published: March 19, 2026, 8:25 p.m. πŸ”„ Last Modified: March 20, 2026, 3:07 p.m.

7.3

CVSS4.0

CVE-2026-33302 - OpenEMR: zhAclCheck Ignores Explicit ACL Denies

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any "allow" (user or group). It never checks for explicit "deny" (allowed=0). As a result, admin…

πŸ“… Published: March 19, 2026, 8:23 p.m. πŸ”„ Last Modified: March 20, 2026, 8:20 p.m.

7.1

CVSS3.1

CVE-2026-27953 - ormar has a Pydantic Validation Bypass via Kwargs Injection in Model Constructor

ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validation by injecting "__pk_only__": true into a JSON request body. By injecting "__pk_only__": true into…

πŸ“… Published: March 19, 2026, 8:23 p.m. πŸ”„ Last Modified: March 20, 2026, 6:10 p.m.

7.5

CVSS3.1

CVE-2026-3547 - wolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validation

Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process cras…

πŸ“… Published: March 19, 2026, 8:20 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

7.2

CVSS4.0

CVE-2026-33321 - OpenEMR has Out-of-Band Server-Side Request Forgery (OOB SSRF)

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An Out-of-Band Server-Side Re…

πŸ“… Published: March 19, 2026, 8:20 p.m. πŸ”„ Last Modified: March 20, 2026, 3:03 p.m.

7.1

CVSS4.0

CVE-2026-33301 - OpenEMR has arbitrary image file read via PDF generator

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An arbitrary file read vulne…

πŸ“… Published: March 19, 2026, 8:10 p.m. πŸ”„ Last Modified: March 20, 2026, 4:16 p.m.

8.3

CVSS4.0

CVE-2026-3549 - ECH parsing heap buffer overflow

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

πŸ“… Published: March 19, 2026, 8:09 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.
Total resulsts: 339064
Page 37 of 33,907
Β« previous page Β» next page
Filters