10

CVSS3.1

CVE-2026-28289 - FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Co…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a maliciou…

📅 Published: March 3, 2026, 10:59 p.m. 🔄 Last Modified: March 3, 2026, 10:59 p.m.

9.2

CVSS4.0

CVE-2026-27971 - Qwik affected by unauthenticated RCE via server$ Deserialization

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where re…

📅 Published: March 3, 2026, 10:55 p.m. 🔄 Last Modified: March 3, 2026, 10:55 p.m.

7.5

CVSS3.1

CVE-2026-27932 - joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library…

📅 Published: March 3, 2026, 10:48 p.m. 🔄 Last Modified: March 3, 2026, 10:48 p.m.

8.6

CVSS4.0

CVE-2026-27905 - BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path…

📅 Published: March 3, 2026, 10:45 p.m. 🔄 Last Modified: March 3, 2026, 10:45 p.m.

8.4

CVSS4.0

CVE-2026-27622 - OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across man…

📅 Published: March 3, 2026, 10:42 p.m. 🔄 Last Modified: March 3, 2026, 10:42 p.m.

8.2

CVSS4.0

CVE-2026-27601 - Underscore.js has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in a Denial of Service (DoS) attack by triggering a stack overflow. Untr…

📅 Published: March 3, 2026, 10:38 p.m. 🔄 Last Modified: March 3, 2026, 10:38 p.m.

9.1

CVSS3.1

CVE-2026-26279 - Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adm…

📅 Published: March 3, 2026, 10:31 p.m. 🔄 Last Modified: March 3, 2026, 10:31 p.m.

8.3

CVSS4.0

CVE-2026-3266 - Improper access control vulnerability has been discovered in OpenText™ Filr.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

📅 Published: March 3, 2026, 10:28 p.m. 🔄 Last Modified: March 3, 2026, 10:28 p.m.

7.4

CVSS3.1

CVE-2026-27981 - HomeBox has an Auth Rate Limit Bypass via IP Spoofing

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-For header, and 3. r.RemoteAddr (TCP connection ad…

📅 Published: March 3, 2026, 10:27 p.m. 🔄 Last Modified: March 3, 2026, 10:27 p.m.

5

CVSS3.1

CVE-2026-27600 - HomeBox affected by Blind SSRF

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to the supplied host, IP address, or port. Although t…

📅 Published: March 3, 2026, 10:23 p.m. 🔄 Last Modified: March 3, 2026, 10:23 p.m.
Total resulsts: 335572
Page 1 of 33,558
» next page
Filters