7.5

CVSS3.1

CVE-2026-33671 - Picomatch has a ReDoS vulnerability via extglob quantifiers

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overla…

📅 Published: March 26, 2026, 9:20 p.m. 🔄 Last Modified: March 27, 2026, 8 p.m.

5.3

CVSS4.0

CVE-2026-0748 - Access bypass in Drupal 7 i18n_node translation UI

In the Drupal 7 Internationalization (i18n) module, the i18n_node submodule allows a user with both "Translate content" and "Administer content translations" permissions to view and attach unpublished nodes via the translation UI and its autocomplete widget. This bypasses intended access controls a…

📅 Published: March 26, 2026, 9:17 p.m. 🔄 Last Modified: March 27, 2026, 3:16 p.m.

5.1

CVSS4.0

CVE-2026-4346 - Cleartext Storage of Administrative and Wi-Fi Credentials via Accessible Serial Interface in TP Lin…

The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of the device’s flash memory while the serial interface remains enabled and protected by weak authentication. An attacker with physical access and the ability to connect to the ser…

📅 Published: March 26, 2026, 9:16 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

9.8

CVSS3.1

CVE-2026-33670 - SiYuan has directory traversal within its publishing service

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

📅 Published: March 26, 2026, 9:15 p.m. 🔄 Last Modified: March 26, 2026, 10:16 p.m.

9.8

CVSS3.1

CVE-2026-33669 - SiYuan has Arbitrary Document Reading within the Publishing Service

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

📅 Published: March 26, 2026, 9:14 p.m. 🔄 Last Modified: March 27, 2026, 8:26 p.m.

6.9

CVSS4.0

CVE-2026-1556 - Information disclosure via file URI overwrite in File (Field) Paths

Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenticated users to disclose other users’ private files via filename‑collision uploads. This can cause hook_node_insert() consumers (for example, email att…

📅 Published: March 26, 2026, 9:14 p.m. 🔄 Last Modified: March 27, 2026, 7:39 p.m.

7.3

CVSS3.1

CVE-2026-33664 - Kestra Vulnerable to Stored Cross-Site Scripting via Flow YAML Fields

Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — description, inputs[].displayName, inputs[].description — through the Markdown.vue component instantiated with html: true. The resulting HTML is injected…

📅 Published: March 26, 2026, 9:13 p.m. 🔄 Last Modified: March 26, 2026, 10:16 p.m.

8.7

CVSS4.0

CVE-2026-3650 - Grassroots DICOM Missing release of memory after effective lifetime

A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously craf…

📅 Published: March 26, 2026, 9:10 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

5.3

CVSS4.0

CVE-2026-4898 - code-projects Online Food Ordering System contact.php cross site scripting

A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the argument Name leads to cross site scripting. It is possible to initiate the attack remotely. The explo…

📅 Published: March 26, 2026, 9:08 p.m. 🔄 Last Modified: March 27, 2026, 8:26 p.m.

8.6

CVSS3.1

CVE-2026-33661 - WeChat Pay callback signature verification bypassed when Host header is localhost

Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can expl…

📅 Published: March 26, 2026, 9:05 p.m. 🔄 Last Modified: March 27, 2026, 8 p.m.
Total resulsts: 341064
Page 37 of 34,107
« previous page » next page
Filters