7.4

CVSS3.1

CVE-2026-27981 - HomeBox has an Auth Rate Limit Bypass via IP Spoofing

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-For header, and 3. r.RemoteAddr (TCP connection adโ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:27 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:27 p.m.

5

CVSS3.1

CVE-2026-27600 - HomeBox affected by Blind SSRF

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although tโ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:23 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:23 p.m.

4.6

CVSS3.1

CVE-2026-26272 - HomeBox affected by Stored XSS via HTML/SVG Attachment Upload

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicโ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:20 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:20 p.m.

9.3

CVSS3.1

CVE-2026-26266 - AliasVault affected by Cross-Site Scripting (XSS) via Email HTML Rendering

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in โ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:16 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:16 p.m.

4.5

CVSS3.1

CVE-2026-25590 - GLPI Inventory Plugin has Reflected XSS in task jobs

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.

๐Ÿ“… Published: March 3, 2026, 10:14 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:14 p.m.

10

CVSS3.1

CVE-2026-24898 - OpenEMR has an Unauthenticated MedEx Token Disclosure

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to completeโ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:10 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:10 p.m.

9.6

CVSS3.1

CVE-2026-25146 - OpenEMR's payments gateway_api_key secret rendered into client JS code

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitraryโ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:08 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:08 p.m.

8.7

CVSS4.0

CVE-2026-24848 - OpenEMR Arbitrary File Write leading to Remote Code Execution

OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary locations on the server filesystem. This vulnerabilitโ€ฆ

๐Ÿ“… Published: March 3, 2026, 10:04 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:04 p.m.

9.8

CVSS3.1

CVE-2026-27012 - Unauthenticated privilege escalation in OpenSTAManager via modules/utenti/actions.php

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/utenti/โ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:53 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 9:53 p.m.

5.1

CVSS4.0

CVE-2026-24415 - OpenSTAManager affected by reflected XSS in modifica_iva.php via righe parameter

OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and earlier contains Reflected XSS vulnerabilities in invoice/order/contract modification modals. The application fails to properly sanitize user-supplied input from the righe GET paraโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:51 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 9:51 p.m.
Total resulsts: 335614
Page 6 of 33,562
ยซ previous page ยป next page
Filters