8.2

CVSS4.0

CVE-2026-33206 - calibre has a path traversal vulnerability

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the fโ€ฆ

๐Ÿ“… Published: March 27, 2026, 1:53 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:01 p.m.

4.8

CVSS4.0

CVE-2026-33205 - calibre has Server-Side Request Forgery in ebook viewer backend

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitraryโ€ฆ

๐Ÿ“… Published: March 27, 2026, 1:52 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:01 p.m.

5.1

CVSS4.0

CVE-2026-33433 - Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject their own canonical version of that headโ€ฆ

๐Ÿ“… Published: March 27, 2026, 1:49 p.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:18 p.m.

6.3

CVSS4.0

CVE-2026-32695 - Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live cluster validation, Knative `rules[].hosts[]` was exโ€ฆ

๐Ÿ“… Published: March 27, 2026, 1:47 p.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:18 p.m.

8.4

CVSS4.0

CVE-2025-13478 - Cache Misconfiguration Leading to Cross-User Data Exposure

Cache misconfiguration vulnerability in OpenText Identity Manager on Windows, Linux allows remote authenticated users to obtain another user's session data via insecure application cache handling. This issue affects Identity Manager: 25.2(v4.10.1).

๐Ÿ“… Published: March 27, 2026, 1:43 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

5.1

CVSS4.0

CVE-2026-32859 - ByteDance DeerFlow Stored XSS via Inline Artifact Rendering

ByteDance Deer-Flow versions prior to commit 5dbb362ย contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to execute arbitrary scripts by uploading malicious HTML or script content as artifacts. Attackers can store malicious content that executes in the broโ€ฆ

๐Ÿ“… Published: March 27, 2026, 1:41 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.3

CVSS4.0

CVE-2026-4982 - Unauthorized access to chat contents

A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or channels in other worlds on the same server due to a bug in the reporting feature. The exploitability is limited by the fact that the attacker needs to know the internal channelโ€ฆ

๐Ÿ“… Published: March 27, 2026, 12:32 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

8.7

CVSS4.0

CVE-2026-25099 - Remote Code Execution via Unrestricted File Upload in Bludit

Bluditโ€™s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

๐Ÿ“… Published: March 27, 2026, 11:55 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

4.8

CVSS4.0

CVE-2026-25100 - Stored XSS via SVG File Upload in Bludit

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author, Editor, or Administrator) can upload an SVG file containing a malicious payload, which is executed when a victim visits the URL of tโ€ฆ

๐Ÿ“… Published: March 27, 2026, 11:55 a.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:55 a.m.

4.8

CVSS4.0

CVE-2026-25101 - Session Fixation in Bludit

Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2.

๐Ÿ“… Published: March 27, 2026, 11:55 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:38 a.m.
Total resulsts: 349182
Page 834 of 34,919
ยซ previous page ยป next page
Filters