6.8

CVSS3.1

CVE-2026-32103 - StudioCMS: IDOR โ€” Admin-to-Owner Account Takeover via Password Reset Link Generation

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset-link endpoint allows any authenticated user with admin privileges to generate a password reset token for any other user, including the owner account.โ€ฆ

๐Ÿ“… Published: March 11, 2026, 8:06 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

7.1

CVSS4.0

CVE-2026-32102 - OliveTin Unauthorized Action Output Disclosure via EventStream

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTinโ€™s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can recโ€ฆ

๐Ÿ“… Published: March 11, 2026, 8:05 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

7.6

CVSS3.1

CVE-2026-32101 - StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() function is declared async (returns Promise<boolean>) but is called without await in both the POST and PUT handlers. Since a Promise object is always truthyโ€ฆ

๐Ÿ“… Published: March 11, 2026, 8:03 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

6.9

CVSS4.0

CVE-2026-3954 - OpenBMB XAgent workspace.py workspace path traversal

A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application/routers/workspace.py. This manipulation of the argument file_name causes path traversal. The attack may be initiated remotely. The exploit has been mโ€ฆ

๐Ÿ“… Published: March 11, 2026, 8:02 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:30 p.m.

5.1

CVSS4.0

CVE-2026-32234 - Parse Server has a SQL injection via query field name when using PostgreSQL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in query constraints when Parse Server is configured with Postgโ€ฆ

๐Ÿ“… Published: March 11, 2026, 7:58 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

6.9

CVSS4.0

CVE-2026-32098 - Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacker can exploit LiveQuery subscriptions to infer the values of protected fields without directly receiving them. By subscribing with a WHERE clause thatโ€ฆ

๐Ÿ“… Published: March 11, 2026, 7:57 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

8.6

CVSS4.0

CVE-2026-32097 - PingPong has improper access control in thread file endpoints allows access outside intended scope

PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrieve or delete files outside the intended authorization scope. This issue could result in retrieval or deletion of private files, including user-uploadeโ€ฆ

๐Ÿ“… Published: March 11, 2026, 7:55 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

9.3

CVSS3.1

CVE-2026-32096 - Plunk has SSRF via unvalidated AWS SNS SubscriptionConfirmation in POST /webhooks/sns

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could send a crafted request that caused the server to make an arbitrary outbound HTTP GET request to anโ€ฆ

๐Ÿ“… Published: March 11, 2026, 7:53 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

5.4

CVSS3.1

CVE-2026-32095 - Plunk has Stored Cross-Site Scripting (XSS) via SVG File Upload

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted SVG files, which browsers treat as active documents capable of executing embedded JavaScript, creating a stored XSS vulnerability. This vulnerability is fixed in 0.7.1.

๐Ÿ“… Published: March 11, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.

6.9

CVSS4.0

CVE-2026-32094 - Shescape escape() leaves bracket glob expansion active on Bash, BusyBox, and Dash

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, BusyBox sh, and Dash. Applications that interpolate the return value directly into a shell command string can cause an attacker-controlled value like secโ€ฆ

๐Ÿ“… Published: March 11, 2026, 7:50 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:37 p.m.
Total resulsts: 349182
Page 1170 of 34,919
ยซ previous page ยป next page
Filters