7.6

CVSS3.1

CVE-2026-34365 - InvoiceShelf: SSRF in Estimate PDF Rendering via Unsanitised HTML in Notes Field

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Estimate PDF generation module. User-supplied HTML in the estimate Notes field…

πŸ“… Published: March 31, 2026, 7:44 p.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

8.2

CVSS4.0

CVE-2026-34784 - Parse Server: Streaming file download bypasses afterFind file trigger authorization

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the…

πŸ“… Published: March 31, 2026, 7:39 p.m. πŸ”„ Last Modified: April 2, 2026, 8:11 p.m.

8.2

CVSS4.0

CVE-2026-34215 - Parse Server: Auth data exposed via verify password endpoint

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, recovery codes, and OAuth access tokens. An attacker …

πŸ“… Published: March 31, 2026, 7:34 p.m. πŸ”„ Last Modified: April 3, 2026, 5:16 p.m.

6.1

CVSS3.1

CVE-2026-34206 - Captcha Protect: Reflected XSS in challenge page via unsanitized destination rendered with text/tem…

Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepte…

πŸ“… Published: March 31, 2026, 7:34 p.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

7.1

CVSS4.0

CVE-2026-34204 - MinIO is Vulnerable to SSE Metadata Injection via Replication Headers

MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* h…

πŸ“… Published: March 31, 2026, 7:30 p.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

8.7

CVSS4.0

CVE-2026-5211 - D-Link DNS-1550-04 app_mgr.cgi UPnP_AV_Server_Path_Del stack-based overflow

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnP_AV_…

πŸ“… Published: March 31, 2026, 7:30 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

2.7

CVSS3.1

CVE-2026-34203 - Nautobot: Management of users via REST API does not apply configured password validators

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (which defaults to an empty list, i.e., no specifi…

πŸ“… Published: March 31, 2026, 7:27 p.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

8.1

CVSS3.1

CVE-2026-4800 - lodash vulnerable to Code Injection via `_.template` imports key names

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes u…

πŸ“… Published: March 31, 2026, 7:25 p.m. πŸ”„ Last Modified: May 1, 2026, 6:09 p.m.

6.5

CVSS3.1

CVE-2026-2950 - lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check …

πŸ“… Published: March 31, 2026, 7:18 p.m. πŸ”„ Last Modified: April 16, 2026, 9:30 a.m.

9.3

CVSS4.0

CVE-2026-3356 - Missing Authentication for Critical Function vulnerability in Anritsu Remote Spectrum Monitor

The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployme…

πŸ“… Published: March 31, 2026, 6:40 p.m. πŸ”„ Last Modified: April 2, 2026, 7:53 a.m.
Total resulsts: 349182
Page 772 of 34,919
Β« previous page Β» next page
Filters