9.8

CVSS3.1

CVE-2025-70230 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:37 p.m.

9.8

CVSS3.1

CVE-2025-70233 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:36 p.m.

7.5

CVSS3.1

CVE-2025-70949 -

An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 1:36 p.m.

9.3

CVSS3.1

CVE-2025-70948 -

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 1:36 p.m.

5.4

CVSS3.1

CVE-2026-26377 - Koha 25.11 and Earlier: Reflected XSS in News Function

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 10 a.m.

8.8

CVSS3.1

CVE-2025-70995 - Remote Code Execution via Improper Validation of Uploaded web.config in Aranda Service Desk API

An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, wh…

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 11:30 a.m.

9.8

CVSS3.1

CVE-2025-29165 - Privilege Escalation via /etc/shadow.sample on D-Link DIR-1253

An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 9 p.m.

7.8

CVSS3.1

CVE-2025-70616 -

A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the IOCTL handler for code 0x80102058. The vulnerability is caused by missing bounds checking on the user-controlled Options parameter before copying data into a 40-byte stack buffer (…

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 10, 2026, 7:41 p.m.

8.4

CVSS4.0

CVE-2026-2836 - Cache poisoning via insecure-by-default cache key

A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host header (authority). Opera…

πŸ“… Published: March 4, 2026, 11:44 p.m. πŸ”„ Last Modified: April 16, 2026, 1:15 p.m.

9.3

CVSS4.0

CVE-2026-2835 - HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attackers…

πŸ“… Published: March 4, 2026, 11:32 p.m. πŸ”„ Last Modified: April 17, 2026, 1 p.m.
Total resulsts: 346094
Page 1028 of 34,610
Β« previous page Β» next page
Filters