5.3

CVSS3.1

CVE-2026-3210 - Material Icons - Moderately critical - Access bypass - SA-CONTRIB-2026-011

Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4.

πŸ“… Published: March 25, 2026, 3:21 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

6.1

CVSS3.1

CVE-2026-2349 - UI Icons - Critical - Cross-site Scripting - SA-CONTRIB-2026-010

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons allows Cross-Site Scripting (XSS).This issue affects UI Icons: from 0.0.0 before 1.0.1, from 1.1.0 before 1.1.1.

πŸ“… Published: March 25, 2026, 3:21 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

5.4

CVSS3.1

CVE-2026-2348 - Quick Edit - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-009

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1.

πŸ“… Published: March 25, 2026, 3:20 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

4.3

CVSS3.1

CVE-2026-1917 - Login Disable - Less critical - Access bypass - SA-CONTRIB-2026-008

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypass.This issue affects Login Disable: from 0.0.0 before 2.1.3.

πŸ“… Published: March 25, 2026, 3:20 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

3.7

CVSS3.1

CVE-2026-4363 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions.

πŸ“… Published: March 25, 2026, 3:04 p.m. πŸ”„ Last Modified: March 27, 2026, 9:47 a.m.

6.9

CVSS4.0

CVE-2026-33268 - Nanoleaf Lines unauthenticated firmware file store

Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and consume storage resources. Fixed in 12.3.6.

πŸ“… Published: March 25, 2026, 2:21 p.m. πŸ”„ Last Modified: March 26, 2026, 11:43 a.m.

8.8

CVSS3.1

CVE-2026-23514 - Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.

πŸ“… Published: March 25, 2026, 2:19 p.m. πŸ”„ Last Modified: March 29, 2026, 8:28 p.m.

5.4

CVSS3.1

CVE-2026-3591 - A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may le…

πŸ“… Published: March 25, 2026, 1:34 p.m. πŸ”„ Last Modified: March 26, 2026, 12:13 p.m.

6.5

CVSS3.1

CVE-2026-3119 - Authenticated query containing a TKEY record may cause named to terminate unexpectedly

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9…

πŸ“… Published: March 25, 2026, 1:31 p.m. πŸ”„ Last Modified: March 26, 2026, 12:13 p.m.

8.7

CVSS4.0

CVE-2026-4815 - SQL Injection vulnerability in Support Board

A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint.

πŸ“… Published: March 25, 2026, 1:31 p.m. πŸ”„ Last Modified: March 27, 2026, 9:47 a.m.
Total resulsts: 349182
Page 908 of 34,919
Β« previous page Β» next page
Filters