6.5

CVSS3.1

CVE-2026-31949 - LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to crash the Node.js server process by sending malformed requests. The DELETE /api/convos route handler …

📅 Published: March 13, 2026, 7:47 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

7.6

CVSS3.1

CVE-2026-31944 - LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect li…

LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redire…

📅 Published: March 13, 2026, 7:44 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

7.5

CVSS3.1

CVE-2026-31899 - CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

📅 Published: March 13, 2026, 7:38 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

6.5

CVSS3.1

CVE-2025-36368 - IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or …

📅 Published: March 13, 2026, 7:35 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

9.1

CVSS3.1

CVE-2026-31886 - Dagu has a Path Traversal via `dagRunId` in Inline DAG Execution

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to construct a temporary directory path without any format validation. Go's filepath.Join resolves .. segment…

📅 Published: March 13, 2026, 7:32 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

7.5

CVSS3.1

CVE-2026-31882 - Dagu SSE Authentication Bypass in Basic Auth Mode

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all Server-Sent Events (SSE) endpoints are accessible without any credentials. This allows unauthenticated attackers to access real-time DAG e…

📅 Published: March 13, 2026, 7:28 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

5.4

CVSS3.1

CVE-2023-40693 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…

📅 Published: March 13, 2026, 7:25 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

6.8

CVSS3.1

CVE-2026-31864 - JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Applet and VirtualApp upload functionality. This vulnerability can only be exploited by users with administrative privileges…

📅 Published: March 13, 2026, 7:22 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

8.7

CVSS4.0

CVE-2026-31814 - Yamux remote Panic via malformed WindowUpdate credit

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can cause arithmetic overflow in send-window accounting, which triggers a panic in the connection state machine. This is remotely reachable over a normal n…

📅 Published: March 13, 2026, 7:19 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

5

CVSS3.1

CVE-2026-31798 - JumpServer Improper Certificate Validation in Custom SMS API Client

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom SMS API Client. When JumpServer sends MFA/OTP codes via Custom SMS API, an attacker can intercept the request and captu…

📅 Published: March 13, 2026, 7:15 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.
Total resulsts: 347802
Page 985 of 34,781
« previous page » next page
Filters