8.4

CVSS3.1

CVE-2026-33747 - BuildKit vulnerable to malicious frontend causing file escape outside of storage root

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for th…

πŸ“… Published: March 27, 2026, 12:49 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

7.4

CVSS3.1

CVE-2026-33745 - cpp-httplib Client Leaks Authentication Credentials to Untrusted Hosts on Cross-Origin HTTP Redirect

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP redirects (301/302/307/308). A malicious or compro…

πŸ“… Published: March 27, 2026, 12:46 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

7.8

CVSS3.1

CVE-2026-33744 - BentoML has Dockerfile Command Injection via system_packages in bentofile.yaml

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.37, the `docker.system_packages` field in `bentofile.yaml` accepts arbitrary strings that are interpolated directly into Dockerfile `RUN` commands without sanitization. Since `sys…

πŸ“… Published: March 27, 2026, 12:45 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

7.7

CVSS4.0

CVE-2026-33935 - MyTube has Unauthenticated Account Lockout via Shared Login Attempt State

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from password-based authentication by triggering failed login attempts. The application exposes three password verification e…

πŸ“… Published: March 27, 2026, 12:43 a.m. πŸ”„ Last Modified: March 27, 2026, 8:31 a.m.

8.9

CVSS4.0

CVE-2026-33890 - MyTube has an Unauthenticated Admin Privilege Escalation via Passkey Registration

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requir…

πŸ“… Published: March 27, 2026, 12:38 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

7.4

CVSS4.0

CVE-2026-33735 - MyTube has an Improper Access Control that Allows Complete Application Takeover

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a fu…

πŸ“… Published: March 27, 2026, 12:36 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

6.5

CVSS3.1

CVE-2026-33730 - Open Source Point of Sale has an IDOR in Password Change (Home)

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of …

πŸ“… Published: March 27, 2026, 12:30 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

5.8

CVSS4.0

CVE-2026-33729 - OpenFGA has an Authorization Bypass through cached keys

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific conditions, models using conditions with caching enabled can result in two different check requests producing the same cache k…

πŸ“… Published: March 27, 2026, 12:27 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

9.3

CVSS4.0

CVE-2026-33728 - dd-trace-java: Unsafe deserialization in RMI instrumentation may lead to remote code execution

dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to…

πŸ“… Published: March 27, 2026, 12:25 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.

5.4

CVSS3.1

CVE-2026-33726 - Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is…

πŸ“… Published: March 27, 2026, 12:23 a.m. πŸ”„ Last Modified: March 27, 2026, 1:16 a.m.
Total resulsts: 340784
Page 5 of 34,079
Β« previous page Β» next page
Filters