1.9

CVSS4.0

CVE-2026-29173 - Craft Commerce has Stored XSS while updating Order Status from Orders Table

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:54 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:45 a.m.

7.4

CVSS3.1

CVE-2026-2713 - IBM Trusteer Rapport installer affected by uncontrolled search path element vulnerability

IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code on the system, caused by DLL uncontrolled search path element vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerabilโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:53 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:30 a.m.

8.7

CVSS4.0

CVE-2026-29172 - Craft Commerce has a SQL Injection in Commerce Purchasables Table Sorting

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. The sort parameter is split by | and the first part (column name) is passed directly as an array key to orderBy() without whitelist valโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:45 a.m.

2.3

CVSS4.0

CVE-2026-29113 - Craft has a potential information disclosure vulnerability in preview tokens

Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an atโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:44 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:30 a.m.

10

CVSS3.1

CVE-2025-48611 -

In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“… Published: March 10, 2026, 7:33 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 2:51 p.m.

9.7

CVSS3.1

CVE-2026-28495 - GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php

GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enablingโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:25 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:30 a.m.

5.3

CVSS3.1

CVE-2026-26330 - Envoy global rate limit may crash when the response phase limit is enabled and the response phase rโ€ฆ

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit filter, if the response phase limit with apply_on_stream_done in the rate limit configuration is enabled and the response phase limit request fails directly, it may crash Envoy. Whโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:19 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:30 a.m.

5.9

CVSS3.1

CVE-2026-26311 - Envoy HTTP: filter chain execution on reset streams causing UAF crash

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, a logic vulnerability in Envoy's HTTP connection manager (FilterManager) that allows for Zombie Stream Filter Execution. This issue creates a "Use-After-Free" (UAF) or state-corruption window where โ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:14 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:45 a.m.

5.9

CVSS3.1

CVE-2026-26310 - Crash for scoped ip address in Envoy during DNS

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::getAddressWithPort with a scoped IPv6 addresses causes a crash. This utility is called in the data plane from the original_src filter and the dns filter. This vulnerability is fixedโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:08 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 3:30 a.m.

5.3

CVSS3.1

CVE-2026-26309 - Envoy has an off-by-one write in JsonEscaper::escapeString()

Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, an off-by-one write in Envoy::JsonEscaper::escapeString() can corrupt std::string null-termination, causing undefined behavior and potentially leading to crashes or out-of-bounds reads when the resuโ€ฆ

๐Ÿ“… Published: March 10, 2026, 7:04 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:45 a.m.
Total resulsts: 349182
Page 1206 of 34,919
ยซ previous page ยป next page
Filters