0.0

CVE-2026-20426 -

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5538.

๐Ÿ“… Published: March 2, 2026, 8:39 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 9:16 a.m.

0.0

CVE-2026-20425 -

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5539.

๐Ÿ“… Published: March 2, 2026, 8:38 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 9:16 a.m.

0.0

CVE-2026-20423 -

In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956.

๐Ÿ“… Published: March 2, 2026, 8:37 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 9:16 a.m.

9.3

CVSS4.0

CVE-2026-3422 - e-Excellence๏ฝœU-Office Force - Insecure Deserialization

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

๐Ÿ“… Published: March 2, 2026, 6:24 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 6:24 a.m.

5.3

CVSS4.0

CVE-2025-15597 - Dataease SQLBot API Endpoint assistant.py access control

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disโ€ฆ

๐Ÿ“… Published: March 2, 2026, 6:16 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 7:16 a.m.

9.3

CVSS4.0

CVE-2026-3000 - Changing๏ฝœIDExpert Windows Logon Agent - Remote Code Execution

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

๐Ÿ“… Published: March 2, 2026, 6:03 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 7:16 a.m.

6.9

CVSS4.0

CVE-2026-3413 - itsourcecode University Management System admin_single_student.php sql injection

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and mayโ€ฆ

๐Ÿ“… Published: March 2, 2026, 6:02 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 2:09 p.m.

9.3

CVSS4.0

CVE-2026-2999 - Changing๏ฝœIDExpert Windows Logon Agent - Remote Code Execution

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

๐Ÿ“… Published: March 2, 2026, 5:59 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 7:16 a.m.

5.3

CVSS4.0

CVE-2026-3412 - itsourcecode University Management System att_single_view.php cross site scripting

A vulnerability was detected in itsourcecode University Management System 1.0. This affects an unknown part of the file /att_single_view.php. The manipulation of the argument dt results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.

๐Ÿ“… Published: March 2, 2026, 5:32 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 2:11 p.m.

6.9

CVSS4.0

CVE-2026-3411 - itsourcecode University Management System admin_single_student_update.php sql injection

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of the file /admin_single_student_update.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. โ€ฆ

๐Ÿ“… Published: March 2, 2026, 5:02 a.m. ๐Ÿ”„ Last Modified: March 2, 2026, 2:31 p.m.
Total resulsts: 335347
Page 10 of 33,535
ยซ previous page ยป next page
Filters