6.9

CVSS4.0

CVE-2026-34443 - FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the function always returns false without checking any CIDR …

📅 Published: March 31, 2026, 9:28 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

4.8

CVSS3.1

CVE-2026-34441 - cpp-httplib: HTTP Request Smuggling via Unconsumed GET Request Body

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive connections, the unread bo…

📅 Published: March 31, 2026, 9:21 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

9.4

CVSS4.0

CVE-2026-34406 - APTRS: Privilege Escalation via Mass Assignment of is_superuser in User Edit Endpoint

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. Prior to version 2.0.1, the edit_user endpoint (POST /api/auth/edituser/<pk>) allows Any user who can reach that endpoint and sub…

📅 Published: March 31, 2026, 9:18 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.1

CVSS3.1

CVE-2026-34405 - Nuxt OG Image vulnerable to reflected XSS via query parameter injection into HTML attributes

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched i…

📅 Published: March 31, 2026, 9:16 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-34404 - Nuxt OG Image vulnerable to DoS via image generation

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height pa…

📅 Published: March 31, 2026, 9:16 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

5.3

CVSS4.0

CVE-2026-5215 - D-Link DNS-1550-04 network_mgr.cgi cgi_get_ipv6 access control

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cg…

📅 Published: March 31, 2026, 9:15 p.m. 🔄 Last Modified: April 3, 2026, 9:19 a.m.

8.7

CVSS4.0

CVE-2026-5214 - D-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflow

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_addgroup_get_gr…

📅 Published: March 31, 2026, 9:15 p.m. 🔄 Last Modified: April 3, 2026, 9:19 a.m.

6.5

CVSS3.1

CVE-2026-34401 - XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Lo…

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related t…

📅 Published: March 31, 2026, 9:05 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.9

CVSS4.0

CVE-2026-34400 - alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version …

📅 Published: March 31, 2026, 9 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.

6.5

CVSS3.1

CVE-2026-34740 - AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FILTER…

📅 Published: March 31, 2026, 8:57 p.m. 🔄 Last Modified: April 2, 2026, 8:10 p.m.
Total resulsts: 342000
Page 54 of 34,200
« previous page » next page
Filters