5

CVSS3.1

CVE-2026-31798 - JumpServer Improper Certificate Validation in Custom SMS API Client

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom SMS API Client. When JumpServer sends MFA/OTP codes via Custom SMS API, an attacker can intercept the request and captu…

📅 Published: March 13, 2026, 7:15 p.m. 🔄 Last Modified: March 13, 2026, 7:15 p.m.

4.3

CVSS3.1

CVE-2025-14483 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Information Disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.

📅 Published: March 13, 2026, 7:15 p.m. 🔄 Last Modified: March 13, 2026, 7:15 p.m.

4.3

CVSS3.1

CVE-2026-30961 - Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate the total file size against the per-request MaxSize limit. An attacker with a public file request link can split an ov…

📅 Published: March 13, 2026, 7:09 p.m. 🔄 Last Modified: March 13, 2026, 7:09 p.m.

5.4

CVSS3.1

CVE-2025-14504 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus alterin…

📅 Published: March 13, 2026, 7:08 p.m. 🔄 Last Modified: March 13, 2026, 7:08 p.m.

6.5

CVSS3.1

CVE-2026-30955 - Gokapi vulnerable to DoS in E2E Metadata Parser

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users. This vulnerability is fix…

📅 Published: March 13, 2026, 7:07 p.m. 🔄 Last Modified: March 13, 2026, 7:07 p.m.

4.1

CVSS3.1

CVE-2026-30943 - Gokapi has Privilege Escalation in File Replace

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility permission (UserPermListOtherUploads) to delete another user's file by abusing the delete…

📅 Published: March 13, 2026, 7:07 p.m. 🔄 Last Modified: March 13, 2026, 7:07 p.m.

5.3

CVSS4.0

CVE-2026-30915 - SFTPGo improperly sanitizes placeholders in group home directories/key prefixes

SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation issue in the handling of dynamic group paths, for example, home directories or key prefixes. When a group is configured with a dynamic home directory or key prefix using placehol…

📅 Published: March 13, 2026, 7:04 p.m. 🔄 Last Modified: March 13, 2026, 7:04 p.m.

5.3

CVSS4.0

CVE-2026-30914 - SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy

SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths t…

📅 Published: March 13, 2026, 7:02 p.m. 🔄 Last Modified: March 13, 2026, 7:02 p.m.

5

CVSS3.1

CVE-2026-30853 - calibre has a Path Traversal Leading to Arbitrary File Write

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre …

📅 Published: March 13, 2026, 7 p.m. 🔄 Last Modified: March 13, 2026, 7 p.m.

5.4

CVSS3.1

CVE-2026-0835 -

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering t…

📅 Published: March 13, 2026, 6:57 p.m. 🔄 Last Modified: March 13, 2026, 6:58 p.m.
Total resulsts: 337972
Page 7 of 33,798
« previous page » next page
Filters