5

CVSS3.1

CVE-2026-33126 - Frigate has SSRF vulnerability in /ffprobe endpoint

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, the /ffprobe endpoint accepts arbitrary user-controlled URLs without proper validation, allowing Server-Side Request Forgery (SSRF) attacks. An attacker can use the Frigate server…

πŸ“… Published: March 20, 2026, 7:57 p.m. πŸ”„ Last Modified: March 25, 2026, 2:34 p.m.

5.3

CVSS4.0

CVE-2026-4500 - bagofwords1 bagofwords code_execution.py generate_df injection

A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py. Such manipulation leads to injection. The attack may be launched remotely. The exploit is publicly available and might be used. …

πŸ“… Published: March 20, 2026, 7:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.9

CVSS4.0

CVE-2026-4499 - D-Link DIR-820LW SSDP ssdpcgi_main os command injection

A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

πŸ“… Published: March 20, 2026, 7:32 p.m. πŸ”„ Last Modified: April 7, 2026, 8:09 a.m.

6.9

CVSS4.0

CVE-2026-4497 - Totolink WA300 cstecgi.cgi recvUpgradeNewFw os command injection

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and …

πŸ“… Published: March 20, 2026, 7:02 p.m. πŸ”„ Last Modified: April 22, 2026, 3:45 a.m.

8.1

CVSS3.1

CVE-2026-33010 - mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True, allow_methods=["*"], and allow_header…

πŸ“… Published: March 20, 2026, 6:33 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

4.8

CVSS4.0

CVE-2026-4496 - sigmade Git-MCP-Server gitUtils.ts child_process.exec os command injection

A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function child_process.exec of the file src/gitUtils.ts of the component show_merge_diff/quick_merge_summary/show_file_diff. The manipulation results in os comma…

πŸ“… Published: March 20, 2026, 6:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.6

CVSS3.1

CVE-2026-32710 - Heap-based Buffer Overflow in MariaDB

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These co…

πŸ“… Published: March 20, 2026, 6:31 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

7.6

CVSS3.1

CVE-2026-32317 - Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API

Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. B…

πŸ“… Published: March 20, 2026, 6:29 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.

7.6

CVSS3.1

CVE-2026-32318 - Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before…

πŸ“… Published: March 20, 2026, 6:27 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.

4.1

CVSS3.1

CVE-2026-32310 - Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths

Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader resolves keyId.getSchemeSpecificPart()…

πŸ“… Published: March 20, 2026, 6:19 p.m. πŸ”„ Last Modified: March 26, 2026, 12:20 p.m.
Total resulsts: 348624
Page 957 of 34,863
Β« previous page Β» next page
Filters