Skip to content

Menu
  • Home
Menu

CVE-2026-30229 – Parse Server: Endpoint `/loginAs` allows `readOnlyMasterKey` to gain full read and write access as any user

Posted on March 7, 2026

CVE ID :CVE-2026-30229 Published : March 6, 2026, 9:16 p.m. | 3 hours, 34 minutes ago Description :Parse Server is an open source backend that can be deployed to any infrastructure that can run…

CVE-2026-30223 – OliveTin: JWT Audience Validation Bypass in Local Key and HMAC Modes

Posted on March 7, 2026

CVE ID :CVE-2026-30223 Published : March 6, 2026, 9:16 p.m. | 3 hours, 34 minutes ago Description :OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT…

CVE-2026-29789 – Vito: Cross-project privilege escalation in workflow site-creation actions allows unauthorized server modification

Posted on March 7, 2026

CVE ID :CVE-2026-29789 Published : March 6, 2026, 9:16 p.m. | 3 hours, 34 minutes ago Description :Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers….

CVE-2026-3612 – Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection

Posted on March 6, 2026

CVE ID : CVE-2026-3612 Published : March 6, 2026, 1:15 a.m. | 28 minutes ago Description : A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file…

CVE-2026-28710 – Acronis Cyber Protect Authentication Bypass

Posted on March 6, 2026

CVE ID : CVE-2026-28710 Published : March 6, 2026, 12:16 a.m. | 1 hour, 28 minutes ago Description : Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis…

CVE-2026-22552 – ePower epower.ie Missing Authentication for Critical Function

Posted on March 6, 2026

CVE ID : CVE-2026-22552 Published : March 6, 2026, 12:16 a.m. | 1 hour, 28 minutes ago Description : WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate…

CVE-2026-26125 – Payment Orchestrator Service Elevation of Privilege Vulnerability

Posted on March 6, 2026

CVE ID : CVE-2026-26125 Published : March 5, 2026, 11:16 p.m. | 28 minutes ago Description : Payment Orchestrator Service Elevation of Privilege Vulnerability Severity: 8.6 | HIGH Visit the link for more…

CVE-2026-21536 – Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Posted on March 6, 2026

CVE ID : CVE-2026-21536 Published : March 5, 2026, 11:16 p.m. | 28 minutes ago Description : Microsoft Devices Pricing Program Remote Code Execution Vulnerability Severity: 9.8 | CRITICAL Visit the link for…

CVE-2026-29606 – OpenClaw < 2026.2.14 – Webhook Signature Verification Bypass via ngrok Loopback Compatibility

Posted on March 6, 2026

CVE ID : CVE-2026-29606 Published : March 5, 2026, 10:16 p.m. | 1 hour, 28 minutes ago Description : OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that…

CVE-2026-28485 – OpenClaw 2026.1.5 < 2026.2.12 – Missing Authentication in Browser Control HTTP Endpoints

Posted on March 6, 2026

CVE ID : CVE-2026-28485 Published : March 5, 2026, 10:16 p.m. | 1 hour, 28 minutes ago Description : OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control…

Posts pagination

Previous 1 … 98 99 100 … 141 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme