8.2

CVSS4.0

CVE-2026-30925 - Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQueโ€ฆ

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js event loop. This makeโ€ฆ

๐Ÿ“… Published: March 9, 2026, 11:01 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, noon

10

CVSS3.1

CVE-2026-30921 - OneUptime Synthetic Monitor RCE via exposed Playwright browser object

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the current implementation, this untrusted code is run inside Nโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:58 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:15 a.m.

8.6

CVSS3.1

CVE-2026-30920 - OneUptime has broken access control in GitHub App installation flow that allows unauthorized projecโ€ฆ

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for the tโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:57 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:15 a.m.

7.6

CVSS3.1

CVE-2026-30919 - facileManager Affected by Stored Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its subsequent HTTP responses in an unsafe manner. Thiโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:54 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:15 a.m.

7.6

CVSS3.1

CVE-2026-30918 - facileManager Affected by Reflected Cross-Site Scripting (XSS)

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to inject malicious JavaScriโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:53 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:15 a.m.

8.8

CVSS4.0

CVE-2026-30917 - Stored XSS on Bucket namespace pages

Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This vulnerability is fixed inโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:50 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 9:45 a.m.

0.0

CVE-2026-30916 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: Further investigation determined that the software behavior described did not falls within the project's threat model. See https://github.com/github/advisory-database/pull/7206 for more information.

๐Ÿ“… Published: March 9, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 8:16 p.m.

4.6

CVSS3.1

CVE-2026-30913 - flarum/nickname: Display name injection in notification emails (autolink & markdown)

Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting aโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:42 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:15 a.m.

10

CVSS3.1

CVE-2026-30887 - OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the insecure Node.js vm module. By lโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:40 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, noon

5.5

CVSS4.0

CVE-2026-30885 - WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and retrieve playlist information including playlistโ€ฆ

๐Ÿ“… Published: March 9, 2026, 10:35 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 10:15 a.m.
Total resulsts: 349182
Page 1234 of 34,919
ยซ previous page ยป next page
Filters