6.5

CVSS3.1

CVE-2026-34586 - PdfDing: Shared PDF Expiration, Max Views, and Deletion Bypass via Serve/Download Endpoints

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_access_allowed() validates only session existence β€” it does not check SharedPdf.inactive (expiration / max views) or SharedPdf.deleted. The Serve and …

πŸ“… Published: March 31, 2026, 8:27 p.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

9.3

CVSS4.0

CVE-2026-1579 - PX4 Autopilot Missing authentication for critical function

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an unauthenticated party with access to the MAVLink in…

πŸ“… Published: March 31, 2026, 8:20 p.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

3.8

CVSS3.1

CVE-2026-3470 - Improper Input Sanitization in SonicWall Email Security Enables Data Corruption

A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.

πŸ“… Published: March 31, 2026, 8:19 p.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

5.3

CVSS4.0

CVE-2026-34372 - Sulu checks fix permissions for subentities endpoints

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even…

πŸ“… Published: March 31, 2026, 8:19 p.m. πŸ”„ Last Modified: April 10, 2026, 9:45 a.m.

2.7

CVSS3.1

CVE-2026-3469 -

A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.

πŸ“… Published: March 31, 2026, 8:18 p.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

4.8

CVSS3.1

CVE-2026-3468 -

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

πŸ“… Published: March 31, 2026, 8:17 p.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

7.6

CVSS3.1

CVE-2026-34367 - InvoiceShelf: SSRF in Invoice PDF Rendering via Unsanitised HTML in Notes Field

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field i…

πŸ“… Published: March 31, 2026, 8:16 p.m. πŸ”„ Last Modified: April 10, 2026, 9:45 a.m.

8.7

CVSS4.0

CVE-2026-5213 - D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cg…

πŸ“… Published: March 31, 2026, 8:15 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

8.7

CVSS4.0

CVE-2026-5212 - D-Link DNS-1550-04 webdav_mgr.cgi Webdav_Upload_File stack-based overflow

A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This issue affects the function Webdav_…

πŸ“… Published: March 31, 2026, 8:15 p.m. πŸ”„ Last Modified: April 3, 2026, 4:40 p.m.

7.6

CVSS3.1

CVE-2026-34366 - InvoiceShelf: SSRF in Payment Receipt PDF Rendering via Unsanitised HTML in Notes Field

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Payment receipt PDF generation module. User-supplied HTML in the payment Notes…

πŸ“… Published: March 31, 2026, 8:05 p.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.
Total resulsts: 349182
Page 771 of 34,919
Β« previous page Β» next page
Filters