7.1

CVSS3.1

CVE-2026-34604 - @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge. That blocks plain ../ traversal, but it does not resolve symlink or junction targets. If a symlink/junction already exists under the allowed content …

πŸ“… Published: April 1, 2026, 4:05 p.m. πŸ”„ Last Modified: April 8, 2026, 7:57 p.m.

8.1

CVSS3.1

CVE-2026-33949 - @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The…

πŸ“… Published: April 1, 2026, 3:54 p.m. πŸ”„ Last Modified: April 8, 2026, 7:57 p.m.

7.4

CVSS3.1

CVE-2026-35099 - Race Condition in Lakeside SysTrack Agent Enables Local Privilege Escalation

Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.

πŸ“… Published: April 1, 2026, 3:39 p.m. πŸ”„ Last Modified: April 3, 2026, 4:11 p.m.

6.9

CVSS4.0

CVE-2026-34510 - OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders

OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file URLs and UNC-style paths before local-path validation. Attackers can exploit this by providing network-hosted file targets that are treated as local content, bypassing intended a…

πŸ“… Published: April 1, 2026, 3:29 p.m. πŸ”„ Last Modified: April 7, 2026, 7:21 p.m.

4.3

CVSS3.1

CVE-2026-4989 -

Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 20…

πŸ“… Published: April 1, 2026, 3:07 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

5

CVSS3.1

CVE-2026-5175 -

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete their own configured MFA factors and reduce account protection to password-only authentication via crafted HTTP requests.Β  This issue affects Serve…

πŸ“… Published: April 1, 2026, 3:04 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

5

CVSS3.1

CVE-2026-4925 -

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and remove their own multi-factor authentication (MFA) configuration via a crafted request. This issue affects Server: from 2026.1.6 through 2026.1.…

πŸ“… Published: April 1, 2026, 3:02 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

6.5

CVSS3.1

CVE-2026-4927 -

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users OTP keys via an authenticated API request. This issue affects Server: from 2026.1.6 through 2026.1.11.

πŸ“… Published: April 1, 2026, 2:54 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

8.2

CVSS3.1

CVE-2026-4924 -

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the victim account via reuse of a partially authenticated sess…

πŸ“… Published: April 1, 2026, 2:50 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

8.2

CVSS3.1

CVE-2026-4828 -

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.

πŸ“… Published: April 1, 2026, 2:48 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.
Total resulsts: 349182
Page 753 of 34,919
Β« previous page Β» next page
Filters