9.3

CVSS4.0

CVE-2026-34458 - Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandbo…

πŸ“… Published: May 5, 2026, 7:24 p.m. πŸ”„ Last Modified: May 7, 2026, 7:48 p.m.

9.2

CVSS4.0

CVE-2026-34084 - PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wr…

πŸ“… Published: May 5, 2026, 7:22 p.m. πŸ”„ Last Modified: May 5, 2026, 9:30 p.m.

8.3

CVSS4.0

CVE-2026-33975 - twenty-server SSRF protection bypass via IPv4-mapped IPv6 address normalization

Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex …

πŸ“… Published: May 5, 2026, 7:19 p.m. πŸ”„ Last Modified: May 5, 2026, 9:30 p.m.

8.6

CVSS4.0

CVE-2026-7857 - D-Link DI-8100 CGI user_group.asp sprintf buffer overflow

A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file /user_group.asp of the component CGI Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and ma…

πŸ“… Published: May 5, 2026, 7:15 p.m. πŸ”„ Last Modified: May 6, 2026, 5:28 p.m.

8.2

CVSS4.0

CVE-2026-33489 - CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead…

πŸ“… Published: May 5, 2026, 7:13 p.m. πŸ”„ Last Modified: May 8, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-33420 - Vaultwarden missing authorization check allows Manager-role users to enumerate all collections

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling get_org_collections endpoint. T…

πŸ“… Published: May 5, 2026, 7:12 p.m. πŸ”„ Last Modified: May 6, 2026, 2:24 p.m.

9.4

CVSS4.0

CVE-2026-33324 - SQLBot prompt injection allows arbitrary SQL execution and remote code execution

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided question parameter is directly concatenated into the LLM prompt without filtering or escaping, and the …

πŸ“… Published: May 5, 2026, 7:09 p.m. πŸ”„ Last Modified: May 5, 2026, 9 p.m.

8.7

CVSS4.0

CVE-2026-32936 - CoreDNS DoH GET path missing size validation causes CPU and memory amplification

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bo…

πŸ“… Published: May 5, 2026, 7:07 p.m. πŸ”„ Last Modified: May 8, 2026, 4:02 p.m.

8.7

CVSS4.0

CVE-2026-32934 - CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When the worker pool is full, CoreDNS still spawns a go…

πŸ“… Published: May 5, 2026, 7:06 p.m. πŸ”„ Last Modified: May 8, 2026, 4:03 p.m.

8.7

CVSS4.0

CVE-2026-33190 - CoreDNS TSIG authentication bypass on encrypted DNS transports

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it trusts the transport writer's TsigStatus() instead of performing verification itself. The DoH and DoH3 writer's TsigStatus…

πŸ“… Published: May 5, 2026, 7:02 p.m. πŸ”„ Last Modified: May 8, 2026, 4:01 p.m.
Total resulsts: 349182
Page 108 of 34,919
Β« previous page Β» next page
Filters