1.2

CVSS4.0

CVE-2026-3230 - Improper key_share validation in TLS 1.3 HelloRetryRequest

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, res…

πŸ“… Published: March 19, 2026, 8:59 p.m. πŸ”„ Last Modified: March 20, 2026, 5:09 p.m.

5.1

CVSS4.0

CVE-2026-27740 - Discourse has Stored XSS in AI Triage Automation

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and renders it using htmlSafe in the Review Queue interfa…

πŸ“… Published: March 19, 2026, 8:56 p.m. πŸ”„ Last Modified: March 20, 2026, 5:03 p.m.

8.6

CVSS4.0

CVE-2026-32622 - SQLBot: Remote Code Execution via Terminology Poisoning

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, u…

πŸ“… Published: March 19, 2026, 8:55 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-27570 - Discourse Vulnerable to Stored XSS via Shared AI Conversation Onebox

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain…

πŸ“… Published: March 19, 2026, 8:52 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

6.9

CVSS4.0

CVE-2026-27491 - Discourse has a bypass of official warnings messages by non-staff users

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only moderation feature. The vulnerability required the a…

πŸ“… Published: March 19, 2026, 8:47 p.m. πŸ”„ Last Modified: March 20, 2026, 8:20 p.m.

9

CVSS4.0

CVE-2026-30924 - qui CORS Misconfiguration: Arbitrary Origins Trusted

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing any external webpage to make authenticated requests on behalf of a logg…

πŸ“… Published: March 19, 2026, 8:45 p.m. πŸ”„ Last Modified: March 20, 2026, 7:46 p.m.

1.3

CVSS4.0

CVE-2026-4395 - Heap-based buffer overflow in wc_ecc_import_x963_ex KCAPI path

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC public key point. The WOLFSSL_KCAPI_ECC code path copies the input to …

πŸ“… Published: March 19, 2026, 8:41 p.m. πŸ”„ Last Modified: March 20, 2026, 5:09 p.m.

5.3

CVSS3.1

CVE-2026-27454 - Discourse has check revision visibility on posts endpoint

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_to directly without verifying whether the revision was hidde…

πŸ“… Published: March 19, 2026, 8:39 p.m. πŸ”„ Last Modified: March 20, 2026, 5:10 p.m.

9.1

CVSS4.0

CVE-2026-4428 - CRL Distribution Point Scope Check Logic Error in AWS-LC

A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-…

πŸ“… Published: March 19, 2026, 8:37 p.m. πŸ”„ Last Modified: March 20, 2026, 1:39 p.m.

10

CVSS3.1

CVE-2026-30836 - Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

πŸ“… Published: March 19, 2026, 8:37 p.m. πŸ”„ Last Modified: March 20, 2026, 1:39 p.m.
Total resulsts: 339346
Page 64 of 33,935
Β« previous page Β» next page
Filters