8.1

CVSS3.1

CVE-2026-35607 - File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users created via the s…

📅 Published: April 7, 2026, 4:31 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

5.3

CVSS4.0

CVE-2026-35606 - File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the Perm.Download permission flag. All three other con…

📅 Published: April 7, 2026, 4:29 p.m. 🔄 Last Modified: April 8, 2026, 7:47 p.m.

5.3

CVSS3.1

CVE-2025-14944 - Backup Migration <= 2.0.0 - Missing Authorization to Unauthenticated Backup Upload to Offline Stora…

The Backup Migration plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to a missing capability check on the 'initializeOfflineAjax' function and lack of proper nonce verification. The endpoint only validates against hardcoded tokens…

📅 Published: April 7, 2026, 4:26 p.m. 🔄 Last Modified: April 8, 2026, 7:47 p.m.

6.3

CVSS4.0

CVE-2026-35605 - File Browser has an access rule bypass via HasPrefix without trailing separator in path matching

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the Matches() function in rules/rules.go uses strings.HasPrefix() without a trailing directory separator when matching paths against access rules…

📅 Published: April 7, 2026, 4:24 p.m. 🔄 Last Modified: April 9, 2026, 2:32 p.m.

8.2

CVSS4.0

CVE-2026-35604 - File Browser share links remain accessible after Share/Download permissions are revoked

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticat…

📅 Published: April 7, 2026, 4:22 p.m. 🔄 Last Modified: April 8, 2026, 7:47 p.m.

7.5

CVSS4.0

CVE-2026-35585 - File Browser has a Command Injection via Hook Runner

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 through 2.63.1, the hook system in File Browser — which executes administrator-defined shell commands on file events such as upload, rename, and delete…

📅 Published: April 7, 2026, 4:20 p.m. 🔄 Last Modified: April 8, 2026, 7:25 p.m.

5.3

CVSS3.1

CVE-2026-35592 - pyLoad has an Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix …

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/extractors/UnTar.py uses os.path.commonprefix() for its path traversal check, which performs character-level string comparison rather than path-level co…

📅 Published: April 7, 2026, 4:11 p.m. 🔄 Last Modified: April 8, 2026, 7:48 p.m.

6.8

CVSS3.1

CVE-2026-35586 - Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name …

📅 Published: April 7, 2026, 4:09 p.m. 🔄 Last Modified: April 8, 2026, 7:48 p.m.

6.9

CVSS4.0

CVE-2026-35584 - FreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Ma…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation_id}/{thread_id} does not require authentication and does not validate whether the given thread_id belongs to the given conversation_id. This allows any un…

📅 Published: April 7, 2026, 4:07 p.m. 🔄 Last Modified: April 9, 2026, 2:29 p.m.

7.6

CVSS3.1

CVE-2026-39384 - FreeScout Customer Merge Cross-Mailbox Authorization Bypass

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.

📅 Published: April 7, 2026, 4:05 p.m. 🔄 Last Modified: April 8, 2026, 7:48 p.m.
Total resulsts: 343480
Page 72 of 34,348
« previous page » next page
Filters