7.5

CVSS3.1

CVE-2026-4926 - path-to-regexp vulnerable to Denial of Service via sequential optional groups

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Workarounds: Limit the…

📅 Published: March 26, 2026, 6:59 p.m. 🔄 Last Modified: March 27, 2026, 7:44 p.m.

5.5

CVSS4.0

CVE-2026-28503 - Tandoor Recipes has Cross-Space IDOR in SyncViewSet.query_synced_folder: missing space scoping on g…

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.query_synced_folder()` action in `cookbook/views/api.py` (line 903) fetches a Sync object using `get_object_or_404(Sync, pk=pk)` without including `space…

📅 Published: March 26, 2026, 6:55 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

8.1

CVSS3.1

CVE-2026-33149 - Tandoor Recipes Vulnerable to Host Header Injection

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header without validation. The application uses request.build_absolute…

📅 Published: March 26, 2026, 6:53 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

8.8

CVSS3.1

CVE-2026-33506 - DOM-Based XSS in Ory Polis Login Page

Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 contain a DOM-based Cross-Site Scripting (XSS) vulnerability in Ory Polis's login functionality. The application improperly trusts a URL parameter (`callbackUrl…

📅 Published: March 26, 2026, 6:48 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

7.8

CVSS3.1

CVE-2026-33491 - Zen-C has Stack-Based Buffer Overflow in Identifier Mangling

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based buffer overflow vulnerability in the Zen C compiler allows attackers to cause a compiler crash or potentially execute arbitrary code by providing a specially crafted Zen C source…

📅 Published: March 26, 2026, 6:39 p.m. 🔄 Last Modified: March 27, 2026, 3:55 a.m.

7.2

CVSS3.1

CVE-2026-33505 - Ory Keto has a SQL injection via forged pagination tokens

Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are encrypted using the secret configured in `secrets.pagi…

📅 Published: March 26, 2026, 6:37 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

7.2

CVSS3.1

CVE-2026-33504 - Ory Hydra has a SQL injection via forged pagination tokens

Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrustedOAuth2JwtGrantIssuers Admin APIs in Ory Hydra are vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are …

📅 Published: March 26, 2026, 5:38 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

7.2

CVSS3.1

CVE-2026-33503 - Ory Kratos has a SQL injection via forged pagination tokens

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API in Ory Kratos is vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are encrypted using the secret configured…

📅 Published: March 26, 2026, 5:32 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

8.1

CVSS3.1

CVE-2026-33496 - Ory Oathkeeper has an authentication bypass by cache key confusion

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to authentication bypass due to cache key confusion. The `oauth2_introspection` authenticator cache does not disti…

📅 Published: March 26, 2026, 5:29 p.m. 🔄 Last Modified: March 27, 2026, 8:33 a.m.

7.8

CVSS4.0

CVE-2026-32857 - Firecrawl Playwright Service SSRF Protection Bypass via Missing Post-Redirect Validation

Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy validation is applied only to the initial user-supplied URL and not to subsequent redirect destinations. Attackers can supply an ext…

📅 Published: March 26, 2026, 5:29 p.m. 🔄 Last Modified: March 27, 2026, 5:16 p.m.
Total resulsts: 341070
Page 44 of 34,107
« previous page » next page
Filters