6.5

CVSS3.1

CVE-2026-32743 - PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling

PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to Stack-based Buffer Overflow through the MavlinkLogHandler, and are triggered via MAVLink log request. The LogEntry.filepath buffer is 60 bytes, but the sscanf function parses path…

πŸ“… Published: March 18, 2026, 11:26 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

8.6

CVSS3.1

CVE-2026-32255 - Kan is Vulnerable to Unauthenticated SSRF via Attachment Download Endpoint

Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch() server-side, and returns the…

πŸ“… Published: March 18, 2026, 11:11 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

8.3

CVSS4.0

CVE-2026-32805 - Romeo is vulnerable to Archive Slip due to missing checks in sanitization

Romeo gives the capability to reach high code coverage of Go β‰₯1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.2, the `sanitizeArchivePath` function in `webserver/api/v1/decoder.go` (lines 80-88) is vulnerable to a path t…

πŸ“… Published: March 18, 2026, 10:24 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

7.9

CVSS4.0

CVE-2026-32737 - Romeo's invalid NetworkPolicy enables a malicious actor to pivot into another namespace

Romeo gives the capability to reach high code coverage of Go β‰₯1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from the "hardened" namespace to any Pod ou…

πŸ“… Published: March 18, 2026, 10:23 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

2.3

CVSS4.0

CVE-2026-32735 - Unpacking Arbitrary Mustache Template Files via `maven-dependency-plugin`

openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting in version 5.1.1 and prior to version 5.5.1, the parent POM file of this project (`openapi-to-java-records-mustache-templates-parent`), which is used to centralize plugin configura…

πŸ“… Published: March 18, 2026, 10:13 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

9.1

CVSS3.1

CVE-2025-15031 - Path Traversal Vulnerability in mlflow/mlflow

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically, the use of `tarfile.extractall` without path validation enables crafted tar.gz files containing `..` or absolute paths to escape the intended extract…

πŸ“… Published: March 18, 2026, 10:06 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

4.3

CVSS3.1

CVE-2026-32736 - Hytale Modding Wiki has Insecure Direct Object Reference / GDPR PII Exposure

The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object Reference (IDOR) vulnerability in versions of the wiki prior to 1.0.0 exposes mod authors' personal information - including full names and email addresses - to any authenticated …

πŸ“… Published: March 18, 2026, 10:06 p.m. πŸ”„ Last Modified: May 5, 2026, 2:19 p.m.

10

CVSS3.1

CVE-2026-32731 - ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise trav…

πŸ“… Published: March 18, 2026, 10:03 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

8.1

CVSS3.1

CVE-2026-32730 - ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware

ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens β€” where the password was verified but TOTP/M…

πŸ“… Published: March 18, 2026, 10 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.

8.2

CVSS4.0

CVE-2026-33163 - Parse Server leaks protected fields via LiveQuery afterEvent trigger

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of th…

πŸ“… Published: March 18, 2026, 9:58 p.m. πŸ”„ Last Modified: March 25, 2026, 11:51 a.m.
Total resulsts: 349182
Page 1057 of 34,919
Β« previous page Β» next page
Filters