8.7

CVSS3.1

CVE-2026-32277 - Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.

๐Ÿ“… Published: March 23, 2026, 9:22 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

8.6

CVSS4.0

CVE-2026-4611 - TOTOLINK X6000R shttpd setLanCfg privilege escalation

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.

๐Ÿ“… Published: March 23, 2026, 9:13 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 7:14 p.m.

8.8

CVSS3.1

CVE-2026-32276 - Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

๐Ÿ“… Published: March 23, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

5.5

CVSS3.1

CVE-2026-29111 - systemd: Local unprivileged user can trigger an assert

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this iโ€ฆ

๐Ÿ“… Published: March 23, 2026, 9:03 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

9.3

CVSS4.0

CVE-2025-60949 - Census CSWeb leaked configuration files

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

๐Ÿ“… Published: March 23, 2026, 9 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:20 p.m.

5.1

CVSS4.0

CVE-2025-60948 - Census CSWeb stored XSS

Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha.

๐Ÿ“… Published: March 23, 2026, 9 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:20 p.m.

8.7

CVSS4.0

CVE-2025-60947 - Census CSWeb arbitrary file upload

Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha.

๐Ÿ“… Published: March 23, 2026, 9 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:20 p.m.

8.7

CVSS4.0

CVE-2025-60946 - Census CSWeb path traversal

Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha.

๐Ÿ“… Published: March 23, 2026, 8:59 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 9:21 a.m.

8.6

CVSS4.0

CVE-2026-23882 - Blinko: Admin RCE - MCP Server Command Injection

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying arbitrary commands and arguments, which are executed when testing the connection. This issue has been patched in version 1.8.4.

๐Ÿ“… Published: March 23, 2026, 8:52 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.

6.9

CVSS4.0

CVE-2026-23485 - Blinko: Unauthorized Path Traversal File Enumeration - music-metadata

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumeration of file existence on the server via different error responses. This issue has been patched in version 1.8.4.

๐Ÿ“… Published: March 23, 2026, 8:50 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:36 p.m.
Total resulsts: 340856
Page 134 of 34,086
ยซ previous page ยป next page
Filters