6.5

CVSS3.1

CVE-2026-30870 - Some sync filters in PowerSync Service ignored using `config.edition: 3`

PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync streams with config.edition: 3, certain subquery filters were ignored when determining which data to sync to users. Depending on the sync stream configuration, this could result in au…

📅 Published: March 9, 2026, 10:31 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

6.8

CVSS4.0

CVE-2026-28267 - Improper File Access Permissions Allow Non‑Administrative Write to System Directories

Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.

📅 Published: March 9, 2026, 10:28 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

9.3

CVSS3.1

CVE-2026-30869 - SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exploiting double‑encoded traversal sequences, an attacker can access sensitive files such as conf/conf…

📅 Published: March 9, 2026, 10:28 p.m. 🔄 Last Modified: April 17, 2026, noon

9.1

CVSS3.1

CVE-2026-30862 - Critical Stored XSS & Privilege Escalation in Appsmith

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be i…

📅 Published: March 9, 2026, 10:26 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

4.3

CVSS3.1

CVE-2026-29773 - kubewarden-controller cross-namespace data exfiltration via deprecated host callback binding

Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of Kubewarden promises is that configured users can deploy namespaced policies in a safe manner, withou…

📅 Published: March 9, 2026, 10:23 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

8.5

CVSS3.1

CVE-2026-28513 - Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token e…

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse. T…

📅 Published: March 9, 2026, 10:19 p.m. 🔄 Last Modified: April 17, 2026, noon

7.1

CVSS3.1

CVE-2026-28512 - Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an attacker can trick …

📅 Published: March 9, 2026, 10:17 p.m. 🔄 Last Modified: April 17, 2026, noon

7.1

CVSS3.1

CVE-2026-28281 - InstantCMS has Multiple CSRF Vulnerabilities

InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability i…

📅 Published: March 9, 2026, 10:13 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

9.1

CVSS3.1

CVE-2025-11158 - Hitachi Vantara Pentaho Data Integration & Analytics - Missing Authorization

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

📅 Published: March 9, 2026, 10:12 p.m. 🔄 Last Modified: May 6, 2026, 5:50 p.m.

6.8

CVSS3.1

CVE-2026-30937 - ImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a 32-bit unsigned integer overflow in the XWD (X Windows) encoder can cause an undersized heap buffer allocation. When writing a extremely large image an out of b…

📅 Published: March 9, 2026, 9:50 p.m. 🔄 Last Modified: April 17, 2026, noon
Total resulsts: 349182
Page 1235 of 34,919
« previous page » next page
Filters