7.3

CVSS4.0

CVE-2026-33881 - Windmill: Rogue Workspace Admins can inject code via unescaped workspace environment variable inter…

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals without escaping single quotes in the NativeTS executor. A workspace admin who sets a custom environment …

📅 Published: March 27, 2026, 8:34 p.m. 🔄 Last Modified: April 1, 2026, 3:55 a.m.

2.7

CVSS4.0

CVE-2026-33879 - FLIP doesn't have rate limiting or brute-force protection on login

Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-…

📅 Published: March 27, 2026, 8:31 p.m. 🔄 Last Modified: March 30, 2026, 1:26 p.m.

8.7

CVSS4.0

CVE-2026-4976 - Totolink LR350 cstecgi.cgi setWiFiGuestCfg buffer overflow

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and co…

📅 Published: March 27, 2026, 8:29 p.m. 🔄 Last Modified: March 30, 2026, 1:26 p.m.

9.3

CVSS3.1

CVE-2026-33875 - Authenticator Vulnerable to Authentication Flow Hijack

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gemati…

📅 Published: March 27, 2026, 8:25 p.m. 🔄 Last Modified: March 30, 2026, 6:57 p.m.

7.8

CVSS3.1

CVE-2026-33874 - Authenticator vulnerable to Remote Code Execution

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authe…

📅 Published: March 27, 2026, 8:23 p.m. 🔄 Last Modified: March 31, 2026, 6:54 p.m.

8.7

CVSS4.0

CVE-2026-34046 - Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` setting to decide whether to filter by `user_id`. When `AUTO_LOGIN` was `False` (i.e., authentic…

📅 Published: March 27, 2026, 8:06 p.m. 🔄 Last Modified: April 1, 2026, 3:55 a.m.

9.3

CVSS4.0

CVE-2026-33873 - Langflow has Authenticated Code Execution in Agentic Assistant Validation

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to validate generated component code, the implementat…

📅 Published: March 27, 2026, 8:04 p.m. 🔄 Last Modified: April 1, 2026, 3:55 a.m.

7.1

CVSS4.0

CVE-2026-33872 - elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Con…

elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerabili…

📅 Published: March 27, 2026, 8:01 p.m. 🔄 Last Modified: March 30, 2026, 6:58 p.m.

8.7

CVSS4.0

CVE-2026-33871 - Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CO…

📅 Published: March 27, 2026, 7:55 p.m. 🔄 Last Modified: March 30, 2026, 8:10 p.m.

7.5

CVSS3.1

CVE-2026-33870 - Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix …

📅 Published: March 27, 2026, 7:54 p.m. 🔄 Last Modified: March 30, 2026, 8:12 p.m.
Total resulsts: 341554
Page 64 of 34,156
« previous page » next page
Filters