9.3

CVSS4.0

CVE-2026-31856 - Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The amount value is i…

📅 Published: March 11, 2026, 5:14 p.m. 🔄 Last Modified: March 20, 2026, 3:30 p.m.

8.7

CVSS4.0

CVE-2026-31854 - Cursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist Bypass

Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitelist mechanism, such indirect prompt injections co…

📅 Published: March 11, 2026, 5:11 p.m. 🔄 Last Modified: March 23, 2026, 9:55 a.m.

5.7

CVSS3.1

CVE-2026-31853 - ImageMagick has a heap buffer over-write on 32-bit systems in SFW decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when processing extremely large images. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.

📅 Published: March 11, 2026, 5:09 p.m. 🔄 Last Modified: March 20, 2026, 3:30 p.m.

10

CVSS3.1

CVE-2026-31852 - Jellyfin Possible Organization/Secret Compromise from dangerous CI implementation

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this vulnerability enables …

📅 Published: March 11, 2026, 5:04 p.m. 🔄 Last Modified: March 23, 2026, 9:55 a.m.

9.3

CVSS4.0

CVE-2026-31840 - Parse Server has a SQL injection via dot-notation field name in PostgreSQL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through an improper escapi…

📅 Published: March 11, 2026, 4:53 p.m. 🔄 Last Modified: March 20, 2026, 3:30 p.m.

8.2

CVSS3.1

CVE-2026-31839 - Striae has a hash validation utility vulnerability

Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted manifest hash fields that could be modified together with package content, allowing tampered confirmat…

📅 Published: March 11, 2026, 4:46 p.m. 🔄 Last Modified: March 23, 2026, 9:55 a.m.

4.8

CVSS3.1

CVE-2026-31813 - Supabase Auth has insecure Apple and Azure authentication with ID tokens

Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbitrary users using specially crafted ID tokens when the Apple or Azure providers are enabled. The attacker issues a vali…

📅 Published: March 11, 2026, 4:42 p.m. 🔄 Last Modified: March 23, 2026, 9:55 a.m.

6.3

CVSS3.1

CVE-2026-30868 - Cross-Site Request Forgery (CSRF) in opnsense/core

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are accessible via HTTP GET requests without CSRF protection. The framework CSRF validation in ApiControllerBase only applies to POST/PUT/DELETE meth…

📅 Published: March 11, 2026, 4:38 p.m. 🔄 Last Modified: March 20, 2026, 3:30 p.m.

6.8

CVSS3.1

CVE-2026-20118 - Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Ser…

A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could allow an unauthenti…

📅 Published: March 11, 2026, 4:31 p.m. 🔄 Last Modified: March 20, 2026, 3:30 p.m.

6.1

CVSS3.1

CVE-2026-20117 - Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management in…

📅 Published: March 11, 2026, 4:31 p.m. 🔄 Last Modified: March 20, 2026, 3:30 p.m.
Total resulsts: 349182
Page 1178 of 34,919
« previous page » next page
Filters