7.1

CVSS3.1

CVE-2026-33217 - NATS allows MQTT clients to bypass ACL checks

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2…

πŸ“… Published: March 25, 2026, 7:43 p.m. πŸ”„ Last Modified: March 27, 2026, 9:30 a.m.

8.6

CVSS3.1

CVE-2026-33216 - NATS has MQTT plaintext password disclosure

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring…

πŸ“… Published: March 25, 2026, 7:41 p.m. πŸ”„ Last Modified: March 28, 2026, 1:37 a.m.

7.5

CVSS3.1

CVE-2026-29785 - NATS Server panic via malicious compression on leafnode port

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens …

πŸ“… Published: March 25, 2026, 7:38 p.m. πŸ”„ Last Modified: March 28, 2026, 1:34 a.m.

7.5

CVSS3.1

CVE-2026-27889 - NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before authentication, and …

πŸ“… Published: March 25, 2026, 7:36 p.m. πŸ”„ Last Modified: March 27, 2026, 9:30 a.m.

7.2

CVSS3.1

CVE-2026-27602 - Modoboa has an OS Command Injection

Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain names flow directly into shell command strings without any sanitization, a Reseller or SuperAdmin can include shell metac…

πŸ“… Published: March 25, 2026, 6:49 p.m. πŸ”„ Last Modified: March 27, 2026, 9:30 a.m.

6.3

CVSS4.0

CVE-2026-33751 - n8n Vulnerable to LDAP Filter Injection in LDAP Node

n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP node's filter escape logic allowed LDAP metacharacters to pass through unescaped when user-controlled input was interpolated into LDAP search filters. In workflows where external u…

πŸ“… Published: March 25, 2026, 6:47 p.m. πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

6.3

CVSS4.0

CVE-2026-33749 - n8n Vulnerable to XSS via Binary Data Inline HTML Rendering

n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary data object without a filename. The `/rest/binary-data` endpoint served such re…

πŸ“… Published: March 25, 2026, 6:39 p.m. πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

6.3

CVSS4.0

CVE-2026-33724 - n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no

n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git operations explicitly disabled host key verification. A network attacker positioned between the n8n instance and the remote Git server c…

πŸ“… Published: March 25, 2026, 6:26 p.m. πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

5.3

CVSS3.1

CVE-2026-33809 - OOM from malicious IFD offset in golang.org/x/image/tiff

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

πŸ“… Published: March 25, 2026, 6:24 p.m. πŸ”„ Last Modified: April 22, 2026, 6:15 a.m.

4.8

CVSS4.0

CVE-2026-1001 - Domoticz < 2026.1 Stored XSS via Hardware Configuration Endpoint

Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers…

πŸ“… Published: March 25, 2026, 6:12 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.
Total resulsts: 349182
Page 877 of 34,919
Β« previous page Β» next page
Filters