8.1

CVSS3.1

CVE-2026-32729 - Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/veri…

Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enforce any rate limiting, attempt counting, or account lockout mechanism. An attacker who has obtained a user's valid credentials (via phishing, credential stuffing, or data breach) c…

πŸ“… Published: March 13, 2026, 9:41 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

5.3

CVSS3.1

CVE-2026-32724 - PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condit…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the MavlinkShell::available() function. The issue is caused by a race condition between the MAVLink receiver thread (which handles shell creation/destruction) and the telemetry sender th…

πŸ“… Published: March 13, 2026, 9:39 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

8.5

CVSS4.0

CVE-2026-3227 - Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N

A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file th…

πŸ“… Published: March 13, 2026, 9:38 p.m. πŸ”„ Last Modified: April 8, 2026, 8:02 p.m.

7.1

CVSS4.0

CVE-2026-32720 - Improper Access Control in github.com/ctfer-io/monitoring

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-…

πŸ“… Published: March 13, 2026, 9:27 p.m. πŸ”„ Last Modified: April 16, 2026, 2:47 p.m.

4.2

CVSS3.1

CVE-2026-32719 - AnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin Import

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/agents/imported.js downloads a ZIP file from a community hub URL and extracts i…

πŸ“… Published: March 13, 2026, 9:25 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

2.7

CVSS3.1

CVE-2026-32717 - AnythingLLM access control bypass: suspended users can continue using Browser Extension API keys

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT-backed session path, but it does not block them on the browser extension API ke…

πŸ“… Published: March 13, 2026, 9:23 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

3.8

CVSS3.1

CVE-2026-32715 - AnythingLLM Manager Privilege Bypass Allows Access to Admin-Only System Preferences

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, while every other surface that touches the same settings is restricted to admin …

πŸ“… Published: March 13, 2026, 9:22 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

4.3

CVSS3.1

CVE-2026-32713 - PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descript…

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink FTP session validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and WriteFile operations to proceed with invalid sessions or closed file descriptors.…

πŸ“… Published: March 13, 2026, 9:20 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

5.4

CVSS3.1

CVE-2026-32709 - PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVLink FTP implementation allows any MAVLink peer to read, write, create, delete, and rename arbitrary files on the flight controller filesystem without …

πŸ“… Published: March 13, 2026, 9:19 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

7.8

CVSS3.1

CVE-2026-32708 - Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message to force an unbounded stack allocation and copy, ca…

πŸ“… Published: March 13, 2026, 9:18 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.
Total resulsts: 349182
Page 1117 of 34,919
Β« previous page Β» next page
Filters