8.8

CVSS3.1

CVE-2026-29089 - TimescaleDB uses untrusted search path during extension upgrade

TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqualified database objects (tables, functions, operators). If the search_path includes user-writable sc…

πŸ“… Published: March 6, 2026, 5:06 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

7.5

CVSS3.1

CVE-2026-29087 - @hono/node-server: Authorization bypass for protected static paths via encoded slashes in Serve Sta…

@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed w…

πŸ“… Published: March 6, 2026, 5:03 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

7.5

CVSS4.0

CVE-2026-29783 - GitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command exec…

The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server re…

πŸ“… Published: March 6, 2026, 4:39 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

7.3

CVSS3.1

CVE-2026-29082 - Kestra: Stored Cross-Site Scripting in Markdown File Preview

Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (.md) with markdown-it instantiated as html:true and injects the resulting HTML with Vue’s v-html without sanitisation. At time of publication, there a…

πŸ“… Published: March 6, 2026, 4:33 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

8.3

CVSS3.1

CVE-2026-29075 - Mesa: Checking out of untrusted code in `benchmarks.yml` workflow may lead to code execution in pri…

Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit …

πŸ“… Published: March 6, 2026, 4:30 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

8.7

CVSS4.0

CVE-2025-15602 - Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Supe…

πŸ“… Published: March 6, 2026, 4:16 p.m. πŸ”„ Last Modified: April 17, 2026, 9:30 p.m.

8.2

CVSS3.1

CVE-2026-29064 - Zarf: Symlink targets in archives are not validated against destination directory

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or writ…

πŸ“… Published: March 6, 2026, 4:13 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

7.7

CVSS3.1

CVE-2026-26017 - CoreDNS ACL Bypass

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-o…

πŸ“… Published: March 6, 2026, 3:36 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

7.5

CVSS3.1

CVE-2026-26018 - CoreDNS Loop Detection Denial of Service Vulnerability

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-ra…

πŸ“… Published: March 6, 2026, 3:35 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.

6.9

CVSS4.0

CVE-2026-27027 - Everon api.everon.io Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

πŸ“… Published: March 6, 2026, 3:20 p.m. πŸ”„ Last Modified: April 16, 2026, 11:30 a.m.
Total resulsts: 349182
Page 1273 of 34,919
Β« previous page Β» next page
Filters