4.9

CVSS3.1

CVE-2026-4819 - Search Guard audit logs can contain under certain conditions user credentials

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

πŸ“… Published: March 31, 2026, 2:57 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

5.4

CVSS3.1

CVE-2026-22569 - Incorrect startup configuration in ZCC

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

πŸ“… Published: March 31, 2026, 2:54 p.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

6.8

CVSS3.1

CVE-2026-4818 - Some management operations on data streams are not properly restricted when user does not have the …

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.

πŸ“… Published: March 31, 2026, 2:53 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

9.1

CVSS4.0

CVE-2026-34532 - Parse Server: Cloud function validator bypass via prototype chain traversal

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Fun…

πŸ“… Published: March 31, 2026, 2:42 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

4.3

CVSS3.1

CVE-2026-4799 - Open redirect vulnerability in Search Guard Kibana Plugin via manipulated requests

In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

πŸ“… Published: March 31, 2026, 2:41 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

5.3

CVSS4.0

CVE-2026-34373 - Parse Server: GraphQL API endpoint ignores CORS origin restriction

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cross-origin requests from any website. This bypass…

πŸ“… Published: March 31, 2026, 2:38 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

8.2

CVSS4.0

CVE-2026-34363 - Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subscriber concurrently using shared mutable objects. …

πŸ“… Published: March 31, 2026, 2:35 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

7.8

CVSS3.1

CVE-2026-0596 - Command Injection in mlflow/mlflow

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` contains shell metacharacters, such as `$()` or backticks, it …

πŸ“… Published: March 31, 2026, 2:25 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

2.1

CVSS4.0

CVE-2026-34224 - Parse Server: MFA single-use token bypass via concurrent authData login requests

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery code or SMS one-time password can create multiple authenticat…

πŸ“… Published: March 31, 2026, 2:25 p.m. πŸ”„ Last Modified: April 2, 2026, 4:16 p.m.

7.7

CVSS3.1

CVE-2026-34214 - Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON

Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level. This issue has been pat…

πŸ“… Published: March 31, 2026, 2:14 p.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.
Total resulsts: 349182
Page 778 of 34,919
Β« previous page Β» next page
Filters