2.5

CVSS3.1

CVE-2026-27139 - FileInfo can escape from a Root in os

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the fi…

πŸ“… Published: March 6, 2026, 9:28 p.m. πŸ”„ Last Modified: April 21, 2026, 2:32 p.m.

6.1

CVSS3.1

CVE-2026-27142 - URLs in meta content attribute actions are not escaped in html/template

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs in actions…

πŸ“… Published: March 6, 2026, 9:28 p.m. πŸ”„ Last Modified: April 21, 2026, 2:30 p.m.

7.5

CVSS3.1

CVE-2026-25679 - Incorrect parsing of IPv6 host literals in net/url

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

πŸ“… Published: March 6, 2026, 9:28 p.m. πŸ”„ Last Modified: April 21, 2026, 11:45 p.m.

5.9

CVSS3.1

CVE-2026-27138 - Panic in name constraint checking for malformed certificates in crypto/x509

Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains, or those that use TLS.

πŸ“… Published: March 6, 2026, 9:28 p.m. πŸ”„ Last Modified: April 21, 2026, 2:39 p.m.

7.5

CVSS3.1

CVE-2026-27137 - Incorrect enforcement of email constraints in crypto/x509

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

πŸ“… Published: March 6, 2026, 9:28 p.m. πŸ”„ Last Modified: April 21, 2026, 2:40 p.m.

8.5

CVSS3.1

CVE-2026-30242 - Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer

Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing attackers with workspace ADMIN role to create webhooks pointing to private/internal network addresses (10.x.x.x, 172.16.x.x…

πŸ“… Published: March 6, 2026, 9:19 p.m. πŸ”„ Last Modified: April 18, 2026, 10 a.m.

7.5

CVSS3.1

CVE-2026-30244 - Plane: Unauthenticated Workspace Member Information Disclosure

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission clas…

πŸ“… Published: March 6, 2026, 9:19 p.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.

2.7

CVSS4.0

CVE-2026-30241 - Mercurius: queryDepth limit bypassed for WebSocket subscriptions

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections. The depth check is correctly applied to HTTP queries and mutations, but subscription queries are parse…

πŸ“… Published: March 6, 2026, 9:15 p.m. πŸ”„ Last Modified: April 18, 2026, 10 a.m.

5.1

CVSS4.0

CVE-2026-30238 - Group-Office: Reflected XSS in JavaScript context

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in GroupOffice on the external/index flow. The f parameter (Base64 JSON) is decoded and then injected into an inline JavaScript …

πŸ“… Published: March 6, 2026, 9:14 p.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.

2.1

CVSS4.0

CVE-2026-30237 - Group-Office: Self XSS in GroupOffice Installer License Page (install/license.php)

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in the GroupOffice installer, endpoint install/license.php. The POST field license is rendered without escaping inside a <textar…

πŸ“… Published: March 6, 2026, 9:13 p.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.
Total resulsts: 349182
Page 1269 of 34,919
Β« previous page Β» next page
Filters