6.3

CVSS4.0

CVE-2026-33429 - Parse Server: Protected field change detection oracle via LiveQuery watch parameter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter targeting a protected field. Although the protected field value is properly stripped froโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:16 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:19 p.m.

7.1

CVSS4.0

CVE-2026-33421 - Parse Server: LiveQuery bypasses CLP pointer permission enforcement

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does not enforce Class-Level Permission (CLP) pointer permissions (readUserFields and pointerFields). Anyโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:14 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:19 p.m.

7

CVSS4.0

CVE-2026-33409 - Parse Server: Auth provider validation bypass on login via partial authData

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has linked a third-party authentication provider, without knowing โ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:11 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:19 p.m.

9.3

CVSS4.0

CVE-2026-2417 - Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges.

๐Ÿ“… Published: March 24, 2026, 6:06 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:49 p.m.

6.3

CVSS4.0

CVE-2026-33323 - Parse Server: Email verification resend page leaks user existence

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return distinguishable responses depending on whether the provided uโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:06 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:19 p.m.

6.5

CVSS3.1

CVE-2026-33417 - Wallos: Password Reset Tokens Never Expire

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the token validation logic never checks it. A password reset token remains valid indefinโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:01 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:20 a.m.

7.8

CVSS3.1

CVE-2026-1995 - IDrive Cloud Backup Client for Windows contains a privilege escalation vulnerability

IDriveโ€™s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the sysโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:49 p.m.

7.1

CVSS4.0

CVE-2026-33401 - Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helpeโ€ฆ

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left three additional attack surfaces unprotected: the AI Ollama host parameter, the AI rโ€ฆ

๐Ÿ“… Published: March 24, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:20 a.m.

5.4

CVSS3.1

CVE-2026-33400 - Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authenticated user to inject arbitrary JavaScript that executes when any user visits the Settings, Subscrโ€ฆ

๐Ÿ“… Published: March 24, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:20 a.m.

7.7

CVSS3.1

CVE-2026-33399 - Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_webhook_url_for_ssrf() protection was added to the test* notification endpoints but not to the correโ€ฆ

๐Ÿ“… Published: March 24, 2026, 5:43 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:20 a.m.
Total resulsts: 349182
Page 939 of 34,919
ยซ previous page ยป next page
Filters