6.5

CVSS3.1

CVE-2026-32758 - File Browser has an Access Rule Bypass via Path Traversal in Copy/Rename Destination Parameter

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). The destination path in resourcePatchHandler is va…

πŸ“… Published: March 19, 2026, 11:22 p.m. πŸ”„ Last Modified: March 23, 2026, 4:55 p.m.

8.2

CVSS3.1

CVE-2026-32763 - SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `K…

Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The `visitJSONPathLeg()` function appends user-controlled values from `.key()` and `.at()` directly into single-quoted J…

πŸ“… Published: March 19, 2026, 11:14 p.m. πŸ”„ Last Modified: March 21, 2026, 3:05 a.m.

6.5

CVSS3.1

CVE-2026-32697 - SuiteCRM: RecordHandler::getRecord() missing ACLAccess('view') check allows any authenticated user …

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, the `RecordHandler::getRecord()` method retrieves any record by module and ID without checking the current user's ACL view permission. The companion `saveRecord()` meth…

πŸ“… Published: March 19, 2026, 11:13 p.m. πŸ”„ Last Modified: March 23, 2026, 4:42 p.m.

5.4

CVSS3.1

CVE-2026-32757 - Admidio: HTMLPurifier Bypass in eCard Message Allows HTML Email Injection

Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POST['ecard_message'] value instead of the HTMLPurifier-sanitized $formValues['ecard_message'] when constructing the greeting card HTML. This allows an authenticated attacker to inje…

πŸ“… Published: March 19, 2026, 11:12 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.6

CVSS4.0

CVE-2026-29109 - SuiteCRM Authenticated Remote Code Execution via Unsafe Deserialization in SavedSearch Filter Proce…

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to and including 8.9.2 contain an unsafe deserialization vulnerability in the SavedSearch filter processing component that allows an authenticated administrator to execute arbitrary…

πŸ“… Published: March 19, 2026, 11:12 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

6.5

CVSS3.1

CVE-2026-29108 - Authenticated SuiteCRM Users Can Retrieve The Password Hash of Any User

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and MFA configuration. As …

πŸ“… Published: March 19, 2026, 11:10 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.8

CVSS3.1

CVE-2026-33289 - SuiterCRM has LDAP Filter Injection in Authentication Module

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. The application fails to properly sanitize user-supplied input before embedding i…

πŸ“… Published: March 19, 2026, 11:09 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.8

CVSS3.1

CVE-2026-33288 - SuiteCRM has Authenticated SQL Injection in Authentication Module

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, a SQL Injection vulnerability exists in the SuiteCRM authentication mechanisms when directory support is enabled. The application fails to properly sanitize …

πŸ“… Published: March 19, 2026, 11:08 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.8

CVSS3.1

CVE-2026-32756 - Admidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files Module

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within UploadHandlerFile.php, an authent…

πŸ“… Published: March 19, 2026, 11:08 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.1

CVSS3.1

CVE-2026-29189 - SuiteCRM has a REST API V8 IDOR: Missing ACL Checks on User Preferences and Relationship Endpoints

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, the SuiteCRM REST API V8 has missing ACL (Access Control List) checks on several endpoints, allowing authenticated users to access and manipulate data they s…

πŸ“… Published: March 19, 2026, 11:05 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.
Total resulsts: 340077
Page 126 of 34,008
Β« previous page Β» next page
Filters