4.8

CVSS3.1

CVE-2026-33869 - Mastodon has a denial of service for quote authorization

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vuln…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: March 30, 2026, 8:57 p.m.

4.3

CVSS3.1

CVE-2026-33868 - Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can craft a specially enc…

📅 Published: March 27, 2026, 7:50 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

8.9

CVSS4.0

CVE-2026-33765 - Pi-hole Web Interface has a Command Injection Vulnerability

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] paramete…

📅 Published: March 27, 2026, 7:46 p.m. 🔄 Last Modified: April 8, 2026, 8:01 p.m.

5.7

CVSS3.1

CVE-2026-33739 - FOG has Stored XSS in Multiple Management Pages

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter san…

📅 Published: March 27, 2026, 7:45 p.m. 🔄 Last Modified: April 8, 2026, 8:01 p.m.

8.9

CVSS4.0

CVE-2026-33654 - Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling

nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channels/email.py`), allowing a remote, unauthenticated attacker to execute arbitrary LLM instructions (and subsequently, system tools) with…

📅 Published: March 27, 2026, 7:43 p.m. 🔄 Last Modified: April 8, 2026, 8:01 p.m.

9.7

CVSS3.1

CVE-2026-34205 - Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mo…

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuratio…

📅 Published: March 27, 2026, 7:41 p.m. 🔄 Last Modified: April 1, 2026, 3:55 a.m.

5.4

CVSS3.1

CVE-2026-34475 - Varnish Cache: Varnish Cache and Varnish Enterprise: Cache poisoning and authentication bypass via …

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass.

📅 Published: March 27, 2026, 7:40 p.m. 🔄 Last Modified: April 22, 2026, 7:40 p.m.

7.3

CVSS4.0

CVE-2026-33045 - Home Assistant has stored XSS in history-graphs

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, simila…

📅 Published: March 27, 2026, 7:39 p.m. 🔄 Last Modified: April 1, 2026, 3:55 a.m.

7.3

CVSS4.0

CVE-2026-33044 - Home Assistant has stored XSS in Map-card through malicious device name

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a …

📅 Published: March 27, 2026, 7:35 p.m. 🔄 Last Modified: April 2, 2026, 1:08 p.m.

7.5

CVSS3.1

CVE-2026-32241 - Flannel vulnerable to cross-node remote code execution via extension backend BackendData injection

Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily prototype new backend types. In versions of Flannel prior to 0.28.2, this Extension backend is vulnerable to a command injection that allo…

📅 Published: March 27, 2026, 7:31 p.m. 🔄 Last Modified: April 8, 2026, 8:01 p.m.
Total resulsts: 349182
Page 825 of 34,919
« previous page » next page
Filters