9.1

CVSS3.1

CVE-2026-34448 - SiYuan: Stored XSS in Attribute View gallery/kanban cover rendering allows arbitrary command execut…

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary …

📅 Published: March 31, 2026, 9:44 p.m. 🔄 Last Modified: April 2, 2026, 7:52 a.m.

7.5

CVSS3.1

CVE-2026-34453 - SiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors …

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark filters bookmark results by calling FilterBlocksByPublishAccess…

📅 Published: March 31, 2026, 9:43 p.m. 🔄 Last Modified: April 2, 2026, 7:52 a.m.

6.3

CVSS4.0

CVE-2026-34451 - Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not …

📅 Published: March 31, 2026, 9:35 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

4.8

CVSS4.0

CVE-2026-34450 - Claude SDK for Python: Insecure Default File Permissions in Local Filesystem Memory Tool

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the local filesystem memory tool in the Anthropic Python SDK created memory files with mode 0o666, leaving them world-readable on systems with a standard umask and wor…

📅 Published: March 31, 2026, 9:32 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

5.8

CVSS4.0

CVE-2026-34452 - Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local filesystem memory tool in the Anthropic Python SDK validated that model-supplied paths resolved inside the sandboxed memory directory, but then returne…

📅 Published: March 31, 2026, 9:32 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

5.4

CVSS3.1

CVE-2026-34442 - FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Reso…

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-34443 - FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR …

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

4.8

CVSS3.1

CVE-2026-34441 - cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive connections, the unread bo…

📅 Published: March 31, 2026, 9:21 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

9.4

CVSS4.0

CVE-2026-34406 - APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edituser/<pk>) allows Any user who can reach that endpoint and sub…

📅 Published: March 31, 2026, 9:18 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.1

CVSS3.1

CVE-2026-34405 - Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributes

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched i…

📅 Published: March 31, 2026, 9:16 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.
Total resulsts: 341931
Page 47 of 34,194
« previous page » next page
Filters