9.9

CVSS3.1

CVE-2026-32938 - SiYuan has an Arbitrary File Read in its Desktop Publish Service

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating paths against a sensitive-path list. Together with GET /asse…

πŸ“… Published: March 20, 2026, 3:19 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-32114 - Discourse's unscoped status lookups leak restricted metadata

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access metadata about AI personas, features, and LLM models by providing their identi…

πŸ“… Published: March 20, 2026, 3:13 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-31869 - Discourse: Composer mentions endpoint leaks hidden group membership through PM `allowed_names` check

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the ComposerController#mentions endpoint reveals hidden group membership to any authenticated user who can message the group. By supplying allowed_names referencing a hidden-membership grou…

πŸ“… Published: March 20, 2026, 3:10 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.3

CVSS3.1

CVE-2026-31805 - Discourse has a poll authorization bypass via post_id array parameter

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass in the poll plugin allowed authenticated users to vote on, remove votes from, or toggle the open/closed status of polls they did not have access to. By passing post_…

πŸ“… Published: March 20, 2026, 3:07 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-30891 - Discourse hasUnauthorized Exposure of Private User Action Types

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user could access another user's private activity due to insufficient authorization checks in the user actions endpoint. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch.

πŸ“… Published: March 20, 2026, 3:02 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-30889 - Discourse has Unauthorized Post Data Exposure in discourse-user-notes

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderator could exploit insufficient authorization checks to access metadata of posts they should not have permission to view. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a…

πŸ“… Published: March 20, 2026, 2:59 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

2.2

CVSS3.1

CVE-2026-30888 - Discourse has moderator privilege escalation via arbitrary post_id in suspend/silence endpoint

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy documents (ToS, guidelines, privacy policy) that they are explicitly prohibited from modifying. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 conta…

πŸ“… Published: March 20, 2026, 2:55 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

8.7

CVSS4.0

CVE-2026-33063 - free5GC AUSF UE Authentication Panic on Nil SuciSupiMap Interface Conversion

free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Service. All deployments of free5GC v4.0.1 using the AUSF UE authentication service (`/nausf-auth/v1/ue-authentications` endpoint) are affected. A remote a…

πŸ“… Published: March 20, 2026, 2:53 a.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

8.2

CVSS4.0

CVE-2026-32935 - phpseclib's AES-CBC unpadding susceptible to padding oracle timing attack

phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.

πŸ“… Published: March 20, 2026, 2:48 a.m. πŸ”„ Last Modified: May 8, 2026, 3:19 p.m.

8.7

CVSS4.0

CVE-2026-33062 - free5GC NRF Discovery EncodeGroupId Function Panics on Malformed group-id-list Parameter

free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `EncodeGroupId` function attempts to access array indices [0], [1],…

πŸ“… Published: March 20, 2026, 2:46 a.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.
Total resulsts: 349182
Page 1026 of 34,919
Β« previous page Β» next page
Filters