Common Vulnerabilities and Exposures (CVE)

CVE-2026-27139

Mar 6, 2026 21:28:14 UTC

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading me...

CVE-2026-25679

Mar 6, 2026 21:28:14 UTC

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVE-2026-27138

Mar 6, 2026 21:28:14 UTC

Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the chain has excluded name constraints. This can crash programs that are either directly verifying X.509 certificate chains...

CVE-2026-27137

Mar 6, 2026 21:28:13 UTC

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last...

CVE-2026-30242

Mar 6, 2026 21:19:24 UTC

Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing attackers with workspace ADMIN role to create webhooks pointing ...

CVE-2026-30244

Mar 6, 2026 21:19:12 UTC

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vul...

CVE-2026-30241

Mar 6, 2026 21:15:33 UTC

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections. The depth check is correctly applied to HTT...

CVE-2026-30238

Mar 6, 2026 21:14:03 UTC

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in GroupOffice on the external/index flow. The f parameter (Base64 JS...

CVE-2026-30237

Mar 6, 2026 21:13:33 UTC

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, and 26.0.10, there is a reflected XSS vulnerability in the GroupOffice installer, endpoint install/license.php. The POST ...

CVE-2026-30231

Mar 6, 2026 21:10:41 UTC

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file routes only block unauthenticated users from accessing private files. Any authenticated, no...

CVE-2026-30230

Mar 6, 2026 21:09:59 UTC

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the thumbnail endpoint does not validate the password for password‑protected files. It checks ownership/admin for p...

CVE-2026-30227

Mar 6, 2026 21:07:49 UTC

MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail Extension (MIME), as defined by numerous IETF specifications. Prior to version 4.15.1, a CRLF injection vulnerability in...

CVE-2025-69534

Mar 6, 2026 21:07:42 UTC

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, an...

CVE-2026-30233

Mar 6, 2026 21:05:36 UTC

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization flaw in OliveTin allows authenticated users with view: false permission to enumerate action bindings and metadata via dash...

CVE-2026-30225

Mar 6, 2026 21:03:55 UTC

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are n...