6.9

CVSS4.0

CVE-2026-4497 - Totolink WA300 cstecgi.cgi recvUpgradeNewFw os command injection

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and …

πŸ“… Published: March 20, 2026, 7:02 p.m. πŸ”„ Last Modified: April 22, 2026, 3:45 a.m.

8.1

CVSS3.1

CVE-2026-33010 - mcp-memory-service's Wildcard CORS with Credentials Enables Cross-Origin Memory Theft

mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True, allow_methods=["*"], and allow_header…

πŸ“… Published: March 20, 2026, 6:33 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

4.8

CVSS4.0

CVE-2026-4496 - sigmade Git-MCP-Server gitUtils.ts child_process.exec os command injection

A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vulnerability is the function child_process.exec of the file src/gitUtils.ts of the component show_merge_diff/quick_merge_summary/show_file_diff. The manipulation results in os comma…

πŸ“… Published: March 20, 2026, 6:32 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

8.6

CVSS3.1

CVE-2026-32710 - Heap-based Buffer Overflow in MariaDB

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These co…

πŸ“… Published: March 20, 2026, 6:31 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

7.6

CVSS3.1

CVE-2026-32317 - Cryptomator for Android: Tampered vault configuration allows MITM attack on Hub API

Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. B…

πŸ“… Published: March 20, 2026, 6:29 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.

7.6

CVSS3.1

CVE-2026-32318 - Cryptomator for IOS: Tampered vault configuration allows MITM attack on Hub API

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before…

πŸ“… Published: March 20, 2026, 6:27 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.

4.1

CVSS3.1

CVE-2026-32310 - Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths

Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader resolves keyId.getSchemeSpecificPart()…

πŸ“… Published: March 20, 2026, 6:19 p.m. πŸ”„ Last Modified: March 26, 2026, 12:20 p.m.

8.7

CVSS4.0

CVE-2026-32309 - Cryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemes

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over pla…

πŸ“… Published: March 20, 2026, 6:19 p.m. πŸ”„ Last Modified: March 27, 2026, 4:16 p.m.

5.1

CVSS4.0

CVE-2026-4495 - atjiu pybbs CommentApiController.java create cross site scripting

A security flaw has been discovered in atjiu pybbs 6.0.0. This impacts the function create of the file src/main/java/co/yiiu/pybbs/controller/api/CommentApiController.java. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released …

πŸ“… Published: March 20, 2026, 6:02 p.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

7.6

CVSS3.1

CVE-2026-32303 - Cryptomator: Tampered vault configuration allows MITM attack on Hub API

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted end…

πŸ“… Published: March 20, 2026, 5:57 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.
Total resulsts: 349182
Page 1013 of 34,919
Β« previous page Β» next page
Filters