8.7

CVSS4.0

CVE-2026-32314 - Yamux remote Panic via malformed Data frame with SYN set and len = 262145

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DEFAULT_CREDIT (e.g. 262145). On the first packet of a new inb…

📅 Published: March 13, 2026, 7:53 p.m. 🔄 Last Modified: March 13, 2026, 7:53 p.m.

8.2

CVSS3.1

CVE-2026-32313 - xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthori…

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover th…

📅 Published: March 13, 2026, 7:50 p.m. 🔄 Last Modified: March 13, 2026, 7:50 p.m.

6.5

CVSS3.1

CVE-2026-31949 - LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to crash the Node.js server process by sending malformed requests. The DELETE /api/convos route handler …

📅 Published: March 13, 2026, 7:47 p.m. 🔄 Last Modified: March 13, 2026, 7:54 p.m.

7.6

CVSS3.1

CVE-2026-31944 - LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect li…

LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redire…

📅 Published: March 13, 2026, 7:44 p.m. 🔄 Last Modified: March 13, 2026, 7:54 p.m.

7.5

CVSS3.1

CVE-2026-31899 - CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

📅 Published: March 13, 2026, 7:38 p.m. 🔄 Last Modified: March 13, 2026, 7:54 p.m.

6.5

CVSS3.1

CVE-2025-36368 - IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or …

📅 Published: March 13, 2026, 7:35 p.m. 🔄 Last Modified: March 13, 2026, 7:53 p.m.

9.1

CVSS3.1

CVE-2026-31886 - Dagu has a Path Traversal via `dagRunId` in Inline DAG Execution

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to construct a temporary directory path without any format validation. Go's filepath.Join resolves .. segment…

📅 Published: March 13, 2026, 7:32 p.m. 🔄 Last Modified: March 13, 2026, 7:32 p.m.

7.5

CVSS3.1

CVE-2026-31882 - Dagu SSE Authentication Bypass in Basic Auth Mode

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all Server-Sent Events (SSE) endpoints are accessible without any credentials. This allows unauthenticated attackers to access real-time DAG e…

📅 Published: March 13, 2026, 7:28 p.m. 🔄 Last Modified: March 13, 2026, 7:28 p.m.

5.4

CVSS3.1

CVE-2023-40693 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…

📅 Published: March 13, 2026, 7:25 p.m. 🔄 Last Modified: March 13, 2026, 7:25 p.m.

6.8

CVSS3.1

CVE-2026-31864 - JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Applet and VirtualApp upload functionality. This vulnerability can only be exploited by users with administrative privileges…

📅 Published: March 13, 2026, 7:22 p.m. 🔄 Last Modified: March 13, 2026, 7:22 p.m.
Total resulsts: 337973
Page 6 of 33,798
« previous page » next page
Filters