7.1

CVSS3.1

CVE-2026-32617 - AnythingLLM Permissable CORS policy

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, On default installations where no password or API key has been configured, all HTTP endpoints and the agent WebSocket lack authentication, and the serveโ€ฆ

๐Ÿ“… Published: March 13, 2026, 8:07 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

8.2

CVSS3.1

CVE-2026-32600 - xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthoโ€ฆ

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recoโ€ฆ

๐Ÿ“… Published: March 13, 2026, 7:58 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

6.9

CVSS4.0

CVE-2026-32594 - Parse Server GraphQL WebSocket endpoint bypasses security middleware

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection controโ€ฆ

๐Ÿ“… Published: March 13, 2026, 7:56 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

5.3

CVSS3.1

CVE-2025-13212 - IBM Aspera Console Denial of Service

IBM Aspera Console 3.3.0 through 3.4.8 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

๐Ÿ“… Published: March 13, 2026, 7:54 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

2.7

CVSS3.1

CVE-2025-13459 - IBM Aspera Console Denial of Service

IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.

๐Ÿ“… Published: March 13, 2026, 7:54 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

5.3

CVSS3.1

CVE-2025-13460 - IBM Aspera Console Information Disclosure

IBM Aspera Console 3.3.0 through 3.4.8 could allow an attacker to enumerate usernames due to an observable response discrepancy.

๐Ÿ“… Published: March 13, 2026, 7:54 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

8.7

CVSS4.0

CVE-2026-32314 - Yamux remote Panic via malformed Data frame with SYN set and len = 262145

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DEFAULT_CREDIT (e.g. 262145). On the first packet of a new inbโ€ฆ

๐Ÿ“… Published: March 13, 2026, 7:53 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

8.2

CVSS3.1

CVE-2026-32313 - xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthoriโ€ฆ

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover thโ€ฆ

๐Ÿ“… Published: March 13, 2026, 7:50 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

6.5

CVSS3.1

CVE-2026-31949 - LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to crash the Node.js server process by sending malformed requests. The DELETE /api/convos route handler โ€ฆ

๐Ÿ“… Published: March 13, 2026, 7:47 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.

7.6

CVSS3.1

CVE-2026-31944 - LibreChat MCP OAuth callback does not validate browser session โ€” allows token theft via redirect liโ€ฆ

LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redireโ€ฆ

๐Ÿ“… Published: March 13, 2026, 7:44 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 1:40 p.m.
Total resulsts: 349182
Page 1122 of 34,919
ยซ previous page ยป next page
Filters