7

CVSS3.1

CVE-2026-32608 - Glances has a Command Injection via Process Names in Action Command Templates

Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to configure shell commands that execute when monitoring thresholds are exceeded. These commands support Mustache template variables (e.g., `{{name}}`, `{{key}}`) that are populated with…

πŸ“… Published: March 18, 2026, 6:03 a.m. πŸ”„ Last Modified: March 24, 2026, 10:59 a.m.

5.9

CVSS3.1

CVE-2025-15363 - Get Use APIs < 2.0.10 - Contributor+ Stored XSS

The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks under certain server configurations.

πŸ“… Published: March 18, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

8.7

CVSS4.0

CVE-2026-32596 - Glances exposes the REST API without authentication

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authentication by default when started with `glances -w`, exposing REST API with sensitive system information including process command-lines containing credentials (passwords, API keys,…

πŸ“… Published: March 18, 2026, 5:18 a.m. πŸ”„ Last Modified: March 24, 2026, 10:59 a.m.

7.7

CVSS3.1

CVE-2026-32606 - IncusOS has a LUKS encryption bypass due to insufficient TPM policy

IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any interaction by the syst…

πŸ“… Published: March 18, 2026, 5:14 a.m. πŸ”„ Last Modified: March 24, 2026, 10:59 a.m.

8.7

CVSS4.0

CVE-2026-32268 - Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability

The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthent…

πŸ“… Published: March 18, 2026, 4:53 a.m. πŸ”„ Last Modified: April 16, 2026, 2:46 p.m.

2.4

CVSS4.0

CVE-2026-32266 - Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability

The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plu…

πŸ“… Published: March 18, 2026, 3:46 a.m. πŸ”„ Last Modified: April 16, 2026, 2:46 p.m.

5.3

CVSS3.1

CVE-2026-1926 - Subscriptions for WooCommerce <= 1.9.2 - Missing Authorization to Unauthenticated Arbitrary Subscri…

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wps_sfw_admin_cancel_susbcription()` function in all versions up to, and including, 1.9.2. This is due to the function being hooked to the `init` actio…

πŸ“… Published: March 18, 2026, 3:37 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.1

CVSS3.1

CVE-2026-1780 - [CR]Paid Link Manager <= 0.5 - Reflected Cross-Site Scripting

The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …

πŸ“… Published: March 18, 2026, 3:37 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.9

CVSS4.0

CVE-2026-32265 - Amazon S3 for Craft CMS has an Information Disclosure vulnerability

The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets the plugin has access to. The `BucketsController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF tok…

πŸ“… Published: March 18, 2026, 3:28 a.m. πŸ”„ Last Modified: April 16, 2026, 2:46 p.m.

7.5

CVSS3.1

CVE-2026-32256 - music-metadata has an infinite loop vulnerability in ASF parser

music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF parser (`parseExtensionObject()` in `lib/asf/AsfParser.ts:112-158`) enters an infinite loop when a sub-object inside the ASF Header Extension Object has `objectSize = 0`. Version 11.1…

πŸ“… Published: March 18, 2026, 3:22 a.m. πŸ”„ Last Modified: March 24, 2026, 10:59 a.m.
Total resulsts: 349182
Page 1066 of 34,919
Β« previous page Β» next page
Filters