5.3

CVSS3.1

CVE-2026-32230 - Uptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of monitors wi…

Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify that the requested monitor belongs to a public group. All other badge endpoints check AND public = 1 in their SQL query b…

πŸ“… Published: March 12, 2026, 6:13 p.m. πŸ”„ Last Modified: March 20, 2026, 3:48 p.m.

5.3

CVSS3.1

CVE-2026-32100 - swag/platform-security: `/api/_info/config` route exposes information about licenses and active sec…

Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7.

πŸ“… Published: March 12, 2026, 6:10 p.m. πŸ”„ Last Modified: April 16, 2026, 2:47 p.m.

7.5

CVSS3.1

CVE-2026-32141 - flatted: Unbounded recursion DoS in parse() revive phase

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack overflo…

πŸ“… Published: March 12, 2026, 6:08 p.m. πŸ”„ Last Modified: March 20, 2026, 3:48 p.m.

9.3

CVSS4.0

CVE-2026-32140 - Dataease: Redshift JDBC RCE Bypass

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to remote code executio…

πŸ“… Published: March 12, 2026, 6:04 p.m. πŸ”„ Last Modified: March 20, 2026, 3:48 p.m.

2

CVSS4.0

CVE-2025-13462 - tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.

πŸ“… Published: March 12, 2026, 5:59 p.m. πŸ”„ Last Modified: May 1, 2026, 3:09 p.m.

5.3

CVSS4.0

CVE-2026-32139 - Dataease: Unfiltered active SVG content leads to Stored XSS

Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads. However, backend validation only checks whether the XML is parseable and whether the root node is svg. It does not sanitize active content such as o…

πŸ“… Published: March 12, 2026, 5:57 p.m. πŸ”„ Last Modified: April 17, 2026, 10 a.m.

9.3

CVSS4.0

CVE-2026-32137 - DataEase SQL Injection Vulnerability

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string, attackers can inject malici…

πŸ“… Published: March 12, 2026, 5:53 p.m. πŸ”„ Last Modified: March 20, 2026, 3:48 p.m.

8.7

CVSS4.0

CVE-2026-32129 - Poseidon V1 variable-length input collision via implicit zero-padding

soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (PoseidonSponge) accepts variable-length inputs without injective padding. When a caller provides fewer inputs than the sponge rate (inputs.len() < T - 1), unused rate positions ar…

πŸ“… Published: March 12, 2026, 5:47 p.m. πŸ”„ Last Modified: April 16, 2026, 2:47 p.m.

8.2

CVSS4.0

CVE-2026-32116 - Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting critical local files, including ~/.ssh/authorized_keys and .bashrc. This c…

πŸ“… Published: March 12, 2026, 5:40 p.m. πŸ”„ Last Modified: March 20, 2026, 3:48 p.m.

4.8

CVSS4.0

CVE-2026-31890 - Inspektor Gadget: Tracing Denial of Service via Event Flooding

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will silently drop events. The …

πŸ“… Published: March 12, 2026, 5:35 p.m. πŸ”„ Last Modified: April 6, 2026, 2:13 p.m.
Total resulsts: 349182
Page 1150 of 34,919
Β« previous page Β» next page
Filters