8.9

CVSS4.0

CVE-2026-31892 - WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in thei…

πŸ“… Published: March 11, 2026, 3:41 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

9.8

CVSS3.1

CVE-2026-28229 - Argo Workflows has unauthorized access to Argo Workflows Template

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing to…

πŸ“… Published: March 11, 2026, 3:37 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

4.3

CVSS3.1

CVE-2026-1732 - Improper Removal of Sensitive Information Before Storage or Transfer in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.

πŸ“… Published: March 11, 2026, 3:37 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

5

CVSS3.1

CVE-2026-3848 - Improper Neutralization of CRLF Sequences ('CRLF Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input vali…

πŸ“… Published: March 11, 2026, 3:37 p.m. πŸ”„ Last Modified: April 16, 2026, 4:38 p.m.

7.3

CVSS4.0

CVE-2025-12690 - Local Privilege Escalation in NGFW Engine

Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19,Β through 7.3.0, through 7.2.4, through 7.1.10.

πŸ“… Published: March 11, 2026, 3:36 p.m. πŸ”„ Last Modified: May 7, 2026, 8:55 p.m.

10

CVSS3.1

CVE-2026-27897 - Vociferous Unauthenticated Remote Path Traversal (RCE via CSRF)

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dia…

πŸ“… Published: March 11, 2026, 3:30 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

8.1

CVSS3.1

CVE-2026-22248 - GLPI affected by Remote Code Execution via malicious upload

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation…

πŸ“… Published: March 11, 2026, 3:27 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

7.5

CVSS3.1

CVE-2026-21888 - MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer()

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This affects 0.24.6 and earlier.

πŸ“… Published: March 11, 2026, 3:22 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

6.8

CVSS3.1

CVE-2026-32229 - Authentication Bypass via Account Mismatch in JetBrains Hub

In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

πŸ“… Published: March 11, 2026, 3:03 p.m. πŸ”„ Last Modified: April 16, 2026, 3:15 a.m.

5.1

CVSS4.0

CVE-2026-3946 - PHPEMS index.php cross site scripting

A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be …

πŸ“… Published: March 11, 2026, 3:02 p.m. πŸ”„ Last Modified: April 22, 2026, 9:27 p.m.
Total resulsts: 349182
Page 1182 of 34,919
Β« previous page Β» next page
Filters