Skip to content

Menu
  • Home
Menu

CVE-2026-4758 – WP Job Portal <= 2.4.9 – Authenticated (Subscriber+) Arbitrary File Deletion via Resume Custom File Field

Posted on March 26, 2026

CVE ID :CVE-2026-4758 Published : March 26, 2026, 12:16 a.m. | 18 minutes ago Description :The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path…

CVE-2026-34055 – OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification

Posted on March 26, 2026

CVE ID :CVE-2026-34055 Published : March 26, 2026, 12:16 a.m. | 18 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version…

CVE-2026-33917 – OpenEMR has SQL Injection in CAMOS Form

Posted on March 26, 2026

CVE ID :CVE-2026-33917 Published : March 26, 2026, 12:16 a.m. | 18 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to…

CVE-2026-33348 – OpenEMR has Stored XSS in patient encounter Eye Exam form $CHRONIC2 and $CHRONIC3

Posted on March 26, 2026

CVE ID :CVE-2026-33348 Published : March 25, 2026, 11:17 p.m. | 1 hour, 17 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Users with…

CVE-2026-29187 – OpenEMR Vulnerable to Authenticated Blind Boolean-Based SQL Injection in new_search_popup.php

Posted on March 26, 2026

CVE ID :CVE-2026-29187 Published : March 25, 2026, 11:17 p.m. | 1 hour, 18 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to…

CVE-2026-3912 – TIBCO ActiveMatrix BusinessWorks Injection Vulnerability

Posted on March 25, 2026

CVE ID :CVE-2026-3912 Published : March 24, 2026, 9:16 p.m. | 3 hours, 18 minutes ago Description :Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of…

CVE-2025-33244 – NVIDIA APEX Deserialization Vulnerability

Posted on March 25, 2026

CVE ID :CVE-2025-33244 Published : March 24, 2026, 9:16 p.m. | 3 hours, 18 minutes ago Description :NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted…

CVE-2026-33511 – pyload-ng: Authentication Bypass via Host Header Injection in ClickNLoad

Posted on March 25, 2026

CVE ID :CVE-2026-33511 Published : March 24, 2026, 8:16 p.m. | 4 hours, 18 minutes ago Description :pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version…

CVE-2026-33419 – MinIO: LDAP login brute-force via user enumeration and missing rate limit

Posted on March 25, 2026

CVE ID :CVE-2026-33419 Published : March 24, 2026, 8:16 p.m. | 4 hours, 18 minutes ago Description :MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor’s STS (Security Token Service) AssumeRoleWithLDAPIdentity…

CVE-2026-33344 – Dagu has an incomplete fix for CVE-2026-27598: path traversal via %2F-encoded slashes in locateDAG

Posted on March 25, 2026

CVE ID :CVE-2026-33344 Published : March 24, 2026, 8:16 p.m. | 4 hours, 18 minutes ago Description :Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version…

Posts pagination

1 2 … 53 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme