4.3

CVSS3.1

CVE-2026-34383 - Admidio: CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can…

πŸ“… Published: March 31, 2026, 8:33 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

4.6

CVSS3.1

CVE-2026-34382 - Admidio: Missing CSRF Protection on Custom List Deletion in mylist_function.php

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authenticated user to a malicious page can silently des…

πŸ“… Published: March 31, 2026, 8:32 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

7.5

CVSS3.1

CVE-2026-34381 - Admidio: Unauthenticated Access to Role-Restricted documents via neutralized .htaccess

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache configuration, which causes Apache to silently igno…

πŸ“… Published: March 31, 2026, 8:31 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.5

CVSS3.1

CVE-2026-34586 - PdfDing: Shared PDF Expiration, Max Views, and Deletion Bypass via Serve/Download Endpoints

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_access_allowed() validates only session existence β€” it does not check SharedPdf.inactive (expiration / max views) or SharedPdf.deleted. The Serve and …

πŸ“… Published: March 31, 2026, 8:27 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

9.3

CVSS4.0

CVE-2026-1579 - PX4 Autopilot Missing authentication for critical function

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink in…

πŸ“… Published: March 31, 2026, 8:20 p.m. πŸ”„ Last Modified: April 2, 2026, 7:52 a.m.

3.8

CVSS3.1

CVE-2026-3470 -

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.

πŸ“… Published: March 31, 2026, 8:19 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

5.3

CVSS4.0

CVE-2026-34372 - Sulu checks fix permissions for subentities endpoints

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even…

πŸ“… Published: March 31, 2026, 8:19 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

2.7

CVSS3.1

CVE-2026-3469 - Denial of Service via Input Validation in SonicWall Email Security

A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

πŸ“… Published: March 31, 2026, 8:18 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

4.8

CVSS3.1

CVE-2026-3468 - Stored XSS in SonicWall Email Security allows admin to execute JavaScript

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

πŸ“… Published: March 31, 2026, 8:17 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

7.6

CVSS3.1

CVE-2026-34367 - InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field i…

πŸ“… Published: March 31, 2026, 8:16 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.
Total resulsts: 341964
Page 53 of 34,197
Β« previous page Β» next page
Filters