9.3

CVSS4.0

CVE-2026-28430 - Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.php

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a predictable legacy password reset mechanism, an atta…

📅 Published: March 16, 2026, 7:13 p.m. 🔄 Last Modified: March 17, 2026, 6:53 p.m.

6.9

CVSS4.0

CVE-2026-29516 - Buffalo TeraStation TS5400R Excessive File Permissions Information Disclosure

Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on …

📅 Published: March 16, 2026, 7:07 p.m. 🔄 Last Modified: March 17, 2026, 4:16 p.m.

7.7

CVSS4.0

CVE-2026-32267 - Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithT…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->ac…

📅 Published: March 16, 2026, 7:04 p.m. 🔄 Last Modified: March 18, 2026, 3:43 p.m.

8.6

CVSS4.0

CVE-2026-32264 - Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and al…

📅 Published: March 16, 2026, 7:02 p.m. 🔄 Last Modified: March 17, 2026, 5:53 p.m.

8.6

CVSS4.0

CVE-2026-32263 - Craft CMS vulnerable to behavior injection RCE via EntryTypesController

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handler…

📅 Published: March 16, 2026, 6:57 p.m. 🔄 Last Modified: March 17, 2026, 5:55 p.m.

5.3

CVSS4.0

CVE-2026-32262 - Craft CMS has a Path Traversal Vulnerability in AssetsController

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitized in a deleteFile() call before Assets::prepareA…

📅 Published: March 16, 2026, 6:57 p.m. 🔄 Last Modified: March 17, 2026, 5:56 p.m.

8.5

CVSS4.0

CVE-2026-32261 - RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin

Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without san…

📅 Published: March 16, 2026, 6:50 p.m. 🔄 Last Modified: March 17, 2026, 9:52 a.m.

7.4

CVSS4.0

CVE-2025-69196 - FastMCP OAuth Proxy token reuse across MCP servers

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for t…

📅 Published: March 16, 2026, 6:07 p.m. 🔄 Last Modified: March 18, 2026, 3:11 p.m.

5.8

CVSS4.0

CVE-2026-4269 - Improper S3 ownership verification in Bedrock AgentCore Starter Toolkit

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before ver…

📅 Published: March 16, 2026, 6:03 p.m. 🔄 Last Modified: March 17, 2026, 9:52 a.m.

8.2

CVSS4.0

CVE-2026-28498 - Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_has…

📅 Published: March 16, 2026, 6:03 p.m. 🔄 Last Modified: March 17, 2026, 8:40 p.m.
Total resulsts: 339064
Page 83 of 33,907
« previous page » next page
Filters