8.3

CVSS4.0

CVE-2026-33407 - Wallos: SSRF via HTTP Proxy Environment Variable

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search…

📅 Published: March 24, 2026, 5:40 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

4.9

CVSS4.0

CVE-2026-33162 - Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entr…

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either s…

📅 Published: March 24, 2026, 5:32 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

6.3

CVSS4.0

CVE-2026-32854 - LibVNCServer httpd proxy NULL Pointer Dereference

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploi…

📅 Published: March 24, 2026, 5:31 p.m. 🔄 Last Modified: March 27, 2026, 3:52 a.m.

1.3

CVSS4.0

CVE-2026-33161 - Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthori…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response dat…

📅 Published: March 24, 2026, 5:31 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

6.9

CVSS4.0

CVE-2026-32853 - LibVNCServer UltraZip Encoding Heap Out-of-bounds Read

LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application crash. Attackers can exploit improper bounds checking in the HandleUltr…

📅 Published: March 24, 2026, 5:30 p.m. 🔄 Last Modified: March 26, 2026, 12:19 p.m.

2.7

CVSS4.0

CVE-2026-33160 - Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform …

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. T…

📅 Published: March 24, 2026, 5:30 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

6.9

CVSS4.0

CVE-2026-33159 - Craft CMS: Unauthenticated users could execute project configuration sync operations that should be…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-chan…

📅 Published: March 24, 2026, 5:28 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

4.9

CVSS4.0

CVE-2026-33158 - Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with an arbitrary assetId that they are not authorized…

📅 Published: March 24, 2026, 5:26 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

8.6

CVSS4.0

CVE-2026-33157 - Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of a previous fix. The existing patches add cleanse…

📅 Published: March 24, 2026, 5:22 p.m. 🔄 Last Modified: March 27, 2026, 9:20 a.m.

2.1

CVSS4.0

CVE-2025-11571 - Command Execution vulnerability in Simplicity Installer

Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The commands allowed to execute can open executables. However, the commands cannot pass parameters or arguments.  To successfully execute this attack, the attacker needs to be on the same…

📅 Published: March 24, 2026, 4:26 p.m. 🔄 Last Modified: March 25, 2026, 8:49 p.m.
Total resulsts: 349182
Page 940 of 34,919
« previous page » next page
Filters