7.5

CVSS3.1

CVE-2026-31899 - CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

📅 Published: March 13, 2026, 7:38 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

6.5

CVSS3.1

CVE-2025-36368 - IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or …

📅 Published: March 13, 2026, 7:35 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

9.1

CVSS3.1

CVE-2026-31886 - Dagu has a Path Traversal via `dagRunId` in Inline DAG Execution

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to construct a temporary directory path without any format validation. Go's filepath.Join resolves .. segment…

📅 Published: March 13, 2026, 7:32 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

7.5

CVSS3.1

CVE-2026-31882 - Dagu SSE Authentication Bypass in Basic Auth Mode

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all Server-Sent Events (SSE) endpoints are accessible without any credentials. This allows unauthenticated attackers to access real-time DAG e…

📅 Published: March 13, 2026, 7:28 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

5.4

CVSS3.1

CVE-2023-40693 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…

📅 Published: March 13, 2026, 7:25 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

6.8

CVSS3.1

CVE-2026-31864 - JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerability exists in JumpServer's Applet and VirtualApp upload functionality. This vulnerability can only be exploited by users with administrative privileges…

📅 Published: March 13, 2026, 7:22 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

8.7

CVSS4.0

CVE-2026-31814 - Yamux remote Panic via malformed WindowUpdate credit

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can cause arithmetic overflow in send-window accounting, which triggers a panic in the connection state machine. This is remotely reachable over a normal n…

📅 Published: March 13, 2026, 7:19 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

5

CVSS3.1

CVE-2026-31798 - JumpServer Improper Certificate Validation in Custom SMS API Client

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly validates certificates in the Custom SMS API Client. When JumpServer sends MFA/OTP codes via Custom SMS API, an attacker can intercept the request and captu…

📅 Published: March 13, 2026, 7:15 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

4.3

CVSS3.1

CVE-2025-14483 - IBM Sterling B2B Integrator and IBM Sterling File Gateway Information Disclosure

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system.

📅 Published: March 13, 2026, 7:15 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.

4.3

CVSS3.1

CVE-2026-30961 - Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate the total file size against the per-request MaxSize limit. An attacker with a public file request link can split an ov…

📅 Published: March 13, 2026, 7:09 p.m. 🔄 Last Modified: March 23, 2026, 1:40 p.m.
Total resulsts: 349182
Page 1123 of 34,919
« previous page » next page
Filters