9.3

CVSS4.0

CVE-2026-33017 - Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attackeโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:52 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 11:45 p.m.

8.2

CVSS4.0

CVE-2026-33013 - Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayTโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:47 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:23 p.m.

7.5

CVSS3.1

CVE-2026-33012 - Micronaut Framework vulnerable to a Denial of Service in HTML error response caching

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an eโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:43 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.

8.7

CVSS4.0

CVE-2026-33011 - Nest Fastify HEAD Request Middleware Bypass

Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be bypassed because Fastify automatically redirects HEAD requests to the corresponding GET handlers (if they exist). As aโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:37 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.1

CVSS4.0

CVE-2026-4470 - itsourcecode Online Frozen Foods Ordering System admin_edit_menu.php sql injection

A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_edit_menu.php. Performing a manipulation of the argument product_name results in sql injection. It is possible to initiate the aโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:32 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.

7.1

CVSS3.1

CVE-2026-32954 - ERP has a possibility SQL Injection vulnerability due to missing validation

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue hasโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:30 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.

4.7

CVSS4.0

CVE-2026-32953 - Tillitis: TKey Client has an Error in Protocol Implementation

Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored, producing the same Compound Device Identifier (CDI)โ€”and thus the same key mโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:24 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:30 a.m.

8.6

CVSS4.0

CVE-2026-32950 - SQLBot: RCE via SQL Injection in Excel Upload Endpoint

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user (even the lowest-privilโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:14 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.

8.7

CVSS4.0

CVE-2026-32949 - SQLBot: SSRF to Arbitrary File Read (AFR) via Rogue MySQL

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the server. An attacker can exploit the /api/v1/dataโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:08 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.

4.6

CVSS4.0

CVE-2026-32947 - Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below, a DNS over HTTPS (DoH) vulnerability allows attackers to bypass egress-policy: block network restrictions by tunneling exfiltrated data through permitted HTTPS endpoints like dnsโ€ฆ

๐Ÿ“… Published: March 20, 2026, 4:03 a.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:09 p.m.
Total resulsts: 349182
Page 1024 of 34,919
ยซ previous page ยป next page
Filters