7.7

CVSS4.0

CVE-2026-34041 - act: Unrestricted set-env and add-path command processing enables environment injection

act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands, which was disabled due to environment injection risks. When a workflow step echoes untrusted data to stdout, an at…

πŸ“… Published: March 31, 2026, 1:43 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

6.5

CVSS3.1

CVE-2026-34036 - Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploi…

πŸ“… Published: March 31, 2026, 1:39 a.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

6.8

CVSS3.1

CVE-2026-33997 - Moby: Off-by-one error in plugin privilege validation

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privi…

πŸ“… Published: March 31, 2026, 1:36 a.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

8.8

CVSS3.1

CVE-2026-34040 - Moby: AuthZ plugin bypass with oversized request body

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

πŸ“… Published: March 31, 2026, 1:36 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

8.1

CVSS3.1

CVE-2026-32727 - SciTokens: Authorization Bypass via Path Traversal in Scope Validation

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to escape the intended directory restriction. This occurs because the library norma…

πŸ“… Published: March 31, 2026, 1:31 a.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

8.1

CVSS3.1

CVE-2026-32716 - SciTokens: Authorization Bypass via Incorrect Scope Path Prefix Checking

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple prefix match (startswith). This allows a token with access to a specific path (e.g., /john) to also access sibling paths that start with the …

πŸ“… Published: March 31, 2026, 1:31 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

9.8

CVSS3.1

CVE-2026-32714 - SciTokens vulnerable to SQL Injection in KeyCache

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries with user-supplied data (such as issuer and key_id). This allowed an attacker t…

πŸ“… Published: March 31, 2026, 1:31 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

9.8

CVSS3.1

CVE-2026-3300 - Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without prope…

πŸ“… Published: March 31, 2026, 1:24 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

7.5

CVSS3.1

CVE-2026-4020 - Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unau…

πŸ“… Published: March 31, 2026, 1:24 a.m. πŸ”„ Last Modified: April 24, 2026, 6:11 p.m.

6.9

CVSS4.0

CVE-2026-5176 - Totolink A3300R cstecgi.cgi setSyslogCfg command injection

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument provided results in command injection. The attack may be initiated remotely. The exploit has been released…

πŸ“… Published: March 31, 2026, 1:15 a.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.
Total resulsts: 349182
Page 788 of 34,919
Β« previous page Β» next page
Filters