7.5

CVSS3.1

CVE-2026-30350 -

An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 8 p.m.

0.0

CVE-2026-31687 - gpio: omap: do not register driver in probe()

In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") registers the omap_mpuio_driver from omap_mpuio_init(), which is called from omap_gpio_probe(). However, it neither makes sense …

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 6:32 p.m.

9.8

CVSS3.1

CVE-2026-35903 -

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP requests within the same…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 11:45 p.m.

6.1

CVSS3.1

CVE-2026-29971 -

A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. User-controlled input is reflected into HTML and JavaScript contexts without proper output encoding, allowing arbitrary JavaScript execution in the victim's browser via the ftpBack…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 11:45 p.m.

5.5

CVSS3.1

CVE-2026-31689 - EDAC/mc: Fix error path ordering in edac_mc_alloc()

In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc() When the mci->pvt_info allocation in edac_mc_alloc() fails, the error path will call put_device() which will end up calling the device's release function. However, the init ord…

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 6:32 p.m.

7.0

CVSS3.1

CVE-2026-31688 - driver core: enforce device_lock for driver_match_device()

In the Linux kernel, the following vulnerability has been resolved: driver core: enforce device_lock for driver_match_device() Currently, driver_match_device() is called from three sites. One site (__device_attach_driver) holds device_lock(dev), but the other two (bind_store and __driver_attach) …

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 6:32 p.m.

8.8

CVSS3.1

CVE-2026-38934 -

Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 11:45 p.m.

6.5

CVSS3.1

CVE-2021-36438 -

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 11:45 p.m.

6.1

CVSS3.1

CVE-2026-38936 - Reflected XSS via namecontains Parameter in diskover‑community Public SelectIndices

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 1:30 p.m.

8.8

CVSS3.1

CVE-2025-69689 - Local Privilege Escalation via Improper Path Handling in Fan Control Open File Dialog

The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied paths with elevated permissions, which can be exploited by a local attacker to perform actions with administrator-level privileges.

πŸ“… Published: April 27, 2026, midnight πŸ”„ Last Modified: April 28, 2026, 1:15 p.m.
Total resulsts: 347742
Page 108 of 34,775
Β« previous page Β» next page
Filters