7.1

CVSS3.1

CVE-2026-32254 - Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic โ€ฆ

Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds includโ€ฆ

๐Ÿ“… Published: March 18, 2026, 3:14 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

9.6

CVSS3.1

CVE-2026-31938 - jsPDF has HTML Injection in New Window paths

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be exploited in the folโ€ฆ

๐Ÿ“… Published: March 18, 2026, 3:05 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

8.1

CVSS3.1

CVE-2026-31898 - jsPDF has a PDF Object Injection via FreeText color

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnotation` method allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to the following method, a user can injeโ€ฆ

๐Ÿ“… Published: March 18, 2026, 3:03 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

7.7

CVSS3.1

CVE-2026-31891 - Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the `/api/content/aggregate/{model}` endpoint iโ€ฆ

๐Ÿ“… Published: March 18, 2026, 2:58 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

6.5

CVSS3.1

CVE-2026-31865 - Elysia Cookie Value Prototype Pollution

Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to version 1.4.27, an Elysia cookie can be overridden by prototype pollution , eg. `__proto__`. This issue is patched in 1.4.27. As a workaround, use t.Cookie validโ€ฆ

๐Ÿ“… Published: March 18, 2026, 2:50 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

7.5

CVSS3.1

CVE-2026-30922 - pyasn1 Vulnerable to Denial of Service via Unbounded Recursion

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUโ€ฆ

๐Ÿ“… Published: March 18, 2026, 2:29 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

9.6

CVSS3.1

CVE-2026-30884 - mdjnelson/moodle-mod_customcert Vulnerable to Authorization Bypass Through User-Controlled Key

mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a teacher who holds `mod/customcert:manage` in any single course can read and silently overwrite certificate elementโ€ฆ

๐Ÿ“… Published: March 18, 2026, 2:26 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 2:46 p.m.

7.5

CVSS3.1

CVE-2026-29112 - @dicebear/converter vulnerable to ncontrolled memory allocation via crafted SVG dimensions

DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `width` and `height` attributes from the input SVG to determine the output canvas size for rasterization (PNG, JPEG, WebP, AVIF). An attacker who can supโ€ฆ

๐Ÿ“… Published: March 18, 2026, 2:19 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

8.4

CVSS4.0

CVE-2026-33058 - Kanboard has Authenticated SQL Injection in Project Permissions Handler

Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQL injection vulnerability. Attackers with the permission to add users to a project can leverage this vulnerability to dump the entirety of the kanboard database. Version 1.2.51 fiโ€ฆ

๐Ÿ“… Published: March 18, 2026, 2:17 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.

7

CVSS4.0

CVE-2026-29056 - Kanboard's privilege escalation via mass assignment in user invite registration allows any invited โ€ฆ

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without filtering out the `role` field. An attacker who receโ€ฆ

๐Ÿ“… Published: March 18, 2026, 1:56 a.m. ๐Ÿ”„ Last Modified: March 24, 2026, 10:59 a.m.
Total resulsts: 349182
Page 1067 of 34,919
ยซ previous page ยป next page
Filters