Recent
File Browser: Path Traversal in Public Share Links Exposes Files Outside Shared Directory
Published 2026-03-05 by GitHub_M
Chamilo LMS has Stored Cross Site Scripting on Social Networks Uploaded Files
Published 2026-03-05 by GitHub_M
File Browser: TUS Delete Endpoint Bypasses Delete Permission Check
Published 2026-03-05 by GitHub_M
OpenReplay: SQL injection in cards/search via unvalidated sort field parameter
Published 2026-03-05 by GitHub_M
Arbitrary Code Execution in NLTK StanfordSegmenter via Untrusted JAR Loading
Published 2026-03-05 by @huntr_ai
UAA User Token Revocation logic error
Published 2026-03-05 by vmware
ZimaOS: Arbitrary Deletion of Internal System Files via API Path Manipulation
Published 2026-03-05 by GitHub_M
Frappe: Possibility of SQL Injection due to improper fieldname sanitization
Published 2026-03-05 by GitHub_M
Frappe: Broken Access Control in DocShare
Published 2026-03-05 by GitHub_M
Frappe: Stored XSS in avatar_macro.html
Published 2026-03-05 by GitHub_M
Load more ↓