8.6

CVSS3.1

CVE-2026-33661 - WeChat Pay callback signature verification bypassed when Host header is localhost

Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can expl…

📅 Published: March 26, 2026, 9:05 p.m. 🔄 Last Modified: March 27, 2026, 8 p.m.

2.3

CVSS4.0

CVE-2026-33658 - Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate CPU…

📅 Published: March 26, 2026, 9:03 p.m. 🔄 Last Modified: March 26, 2026, 10:16 p.m.

4.6

CVSS3.1

CVE-2026-33653 - Uploady Vulnerable to Stored Cross-Site Scripting (XSS)

Ulloady is a file uploader script with multi-file upload support. A Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 3.1.2 due to improper sanitization of filenames during the file upload process. An attacker can upload a file with a malicious filename containing JavaScri…

📅 Published: March 26, 2026, 9 p.m. 🔄 Last Modified: March 27, 2026, 8:16 p.m.

7.1

CVSS3.1

CVE-2026-33645 - Fireshare has Path Traversal Arbitrary File Write in `/api/uploadChunked`

Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked upload endpoint allows an attacker to write arbitrary files outside the intended upload directory. The `checkSum` multipart field is used directly in file…

📅 Published: March 26, 2026, 8:58 p.m. 🔄 Last Modified: March 27, 2026, 8:01 p.m.

9.1

CVSS4.0

CVE-2026-33640 - Outline has a rate limit bypass that allows brute force of email login OTP

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invalidate OTP codes based on amount or frequency of invalid submi…

📅 Published: March 26, 2026, 8:56 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

5.3

CVSS3.1

CVE-2026-33638 - Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public endpoint and returns user records without authentication. This allows remote unauthenticated user enumeration and exposure of user profile metadata. …

📅 Published: March 26, 2026, 8:52 p.m. 🔄 Last Modified: March 27, 2026, 8:19 p.m.

5.4

CVSS3.1

CVE-2026-33742 - Invoice Ninja has Stored XSS via Markdown HTML Injection in Product Notes

Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Product notes fields in Invoice Ninja v5.13.0 allow raw HTML via Markdown rendering, enabling stored XSS. The Markdown parser output was not sanitized with `purify::clean()` before being included i…

📅 Published: March 26, 2026, 8:50 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

5.4

CVSS3.1

CVE-2026-33628 - Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items

Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads to execute when invoices are rendered in the PDF preview or client portal. The l…

📅 Published: March 26, 2026, 8:48 p.m. 🔄 Last Modified: March 27, 2026, 8:31 a.m.

6.7

CVSS3.1

CVE-2026-33623 - PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Comman…

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command injection issue in the orphaned Chrome cleanup path. When an instance is stopped, the Windows cleanup routine builds a PowerShell `-Command` string using…

📅 Published: March 26, 2026, 8:47 p.m. 🔄 Last Modified: March 27, 2026, 8:01 p.m.

6.1

CVSS4.0

CVE-2026-33622 - A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary JavaScript execution through `POST /wait` and `POST /tabs/{id}/wait` when the request uses `fn` mode, even if `security.allowEvaluate` is disabled. `POS…

📅 Published: March 26, 2026, 8:44 p.m. 🔄 Last Modified: March 27, 2026, 8:20 p.m.
Total resulsts: 341065
Page 38 of 34,107
« previous page » next page
Filters