9.8

CVSS3.1

CVE-2025-40926 - Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely

Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be gue…

📅 Published: March 5, 2026, 1:24 a.m. 🔄 Last Modified: April 22, 2026, 11:30 a.m.

8.6

CVSS4.0

CVE-2026-29124 - Multiple SUID Root Binaries in `monitor` User Home Directory Leading to Potential Local Privilege E…

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from t…

📅 Published: March 5, 2026, 1:23 a.m. 🔄 Last Modified: April 17, 2026, 1 p.m.

8.6

CVSS4.0

CVE-2026-29123 - Multiple SUID Root Binaries in `xd` User Home Directory Leading to Potential Local Privilege Escala…

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symli…

📅 Published: March 5, 2026, 1:18 a.m. 🔄 Last Modified: April 18, 2026, 10 a.m.

8.3

CVSS4.0

CVE-2026-29122 - `/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file…

📅 Published: March 5, 2026, 12:53 a.m. 🔄 Last Modified: April 17, 2026, 1 p.m.

8.3

CVSS4.0

CVE-2026-29121 - `/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file …

📅 Published: March 5, 2026, 12:48 a.m. 🔄 Last Modified: April 16, 2026, 1:15 p.m.

7.5

CVSS3.1

CVE-2025-45691 - ragas: arbitrary file read via improper URL validation in multimodal inputs

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.

📅 Published: March 5, 2026, midnight 🔄 Last Modified: March 10, 2026, 7:38 p.m.

9.8

CVSS3.1

CVE-2025-70231 -

D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin, it enters /goform/getAuthCode but fails to filter the value of the FILECODE parameter, resulting in a path traversal vulnerability.

📅 Published: March 5, 2026, midnight 🔄 Last Modified: March 6, 2026, 5:37 p.m.

7.5

CVSS3.1

CVE-2025-69534 - python-markdown: denial of service via malformed HTML-like sequences

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown m…

📅 Published: March 5, 2026, midnight 🔄 Last Modified: March 13, 2026, 1:25 a.m.

8.1

CVSS3.1

CVE-2026-26417 -

A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.

📅 Published: March 5, 2026, midnight 🔄 Last Modified: April 17, 2026, 1 p.m.

7.5

CVSS3.1

CVE-2026-26418 - Unauthenticated Access in Cognix Recon Client Web API Allows Remote Functionality Exfiltration

Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.

📅 Published: March 5, 2026, midnight 🔄 Last Modified: April 16, 2026, 1:15 p.m.
Total resulsts: 346099
Page 1027 of 34,610
« previous page » next page
Filters