10

CVSS3.1

CVE-2026-31957 - Himmelblau unset domain configuration can allow any-tenant authentication at first login for remote…

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrar…

📅 Published: March 11, 2026, 7:25 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

0

CVSS3.1

CVE-2026-31954 - Emlog asynchronous media file deletion missing CSRF protection

Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling CSRF attacks.

📅 Published: March 11, 2026, 7:21 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

6.3

CVSS4.0

CVE-2026-31901 - Parse Server has user enumeration via email verification endpoint

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses depending on whether an email address belongs to an existing user, …

📅 Published: March 11, 2026, 7:18 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

8.7

CVSS4.0

CVE-2026-31900 - Black's vulnerable version parsing leads to RCE in GitHub Action

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct …

📅 Published: March 11, 2026, 7:15 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

9.8

CVSS3.1

CVE-2026-31896 - WeGIA has a Time-Based Blind SQL Injection in remover_produto_ocultar.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then directly concatenates these variables into a SQL qu…

📅 Published: March 11, 2026, 7:10 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

8.8

CVSS3.1

CVE-2026-31895 - WeGIA has a SQL Injection via Direct Query Interpolation in restaurar_produto.php

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_produto.php. The id_produto parameter from $_GET is directly interpolated into SQL queries without para…

📅 Published: March 11, 2026, 7:08 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

6.9

CVSS4.0

CVE-2026-31894 - WeGIA affected by arbitrary file read via symlink in backup restore

WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted contents. Neither the extraction nor the file reading …

📅 Published: March 11, 2026, 7:05 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

4.8

CVSS4.0

CVE-2026-3950 - strukturag libheif stsz/stts track.cc load out-of-bounds

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and m…

📅 Published: March 11, 2026, 7:02 p.m. 🔄 Last Modified: April 22, 2026, 9:30 p.m.

6.7

CVSS3.1

CVE-2026-24510 - Local Privilege Escalation via Improper Privilege Management in Dell Alienware Command Center

Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

📅 Published: March 11, 2026, 6:59 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.

8.9

CVSS3.1

CVE-2026-31889 - Shopware has a potential take over of app credentials

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based auth…

📅 Published: March 11, 2026, 6:56 p.m. 🔄 Last Modified: March 20, 2026, 3:29 p.m.
Total resulsts: 349182
Page 1172 of 34,919
« previous page » next page
Filters