5.3

CVSS4.0

CVE-2026-32699 - FacturaScripts unauthorized modification of immutable nick field via EditUser controller

FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass this restriction by …

πŸ“… Published: May 5, 2026, 7 p.m. πŸ”„ Last Modified: May 5, 2026, 9 p.m.

8.6

CVSS4.0

CVE-2026-7856 - D-Link DI-8100 Web Management url_member.asp buffer overflow

A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the component Web Management Interface. Executing a manipulation of the argument Name can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and …

πŸ“… Published: May 5, 2026, 7 p.m. πŸ”„ Last Modified: May 6, 2026, 5:36 p.m.

8.2

CVSS4.0

CVE-2026-32603 - Sandboxie kernel driver denial of service via malformed IOCTL from sandboxed process

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \Device\SandboxieDrive…

πŸ“… Published: May 5, 2026, 6:57 p.m. πŸ”„ Last Modified: May 7, 2026, 8:02 p.m.

6.8

CVSS4.0

CVE-2026-31893 - Tunnelblick arbitrary file read via symlink following in tunnelblickd

Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix sock…

πŸ“… Published: May 5, 2026, 6:55 p.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.

5.3

CVSS4.0

CVE-2026-31835 - Vaultwarden WebAuthn credential metadata tampered before signature verification

Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags1) based on unverified `authenticatorData` before signature …

πŸ“… Published: May 5, 2026, 6:51 p.m. πŸ”„ Last Modified: May 6, 2026, 12:46 p.m.

8.2

CVSS4.0

CVE-2026-30923 - libModSecurity3 denial of service via segfault when using t:hexDecode on single-character query str…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the t:hexDecode transformation inspects a query string parameter containing a s…

πŸ“… Published: May 5, 2026, 6:46 p.m. πŸ”„ Last Modified: May 7, 2026, 1:41 p.m.

9.8

CVSS3.1

CVE-2026-27960 - OpenCTI privilege escalation and unauthenticated access via default admin account

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin …

πŸ“… Published: May 5, 2026, 6:35 p.m. πŸ”„ Last Modified: May 6, 2026, 3:17 p.m.

8.7

CVSS4.0

CVE-2026-7855 - D-Link DI-8100 HTTP Request tggl.asp tggl_asp buffer overflow

A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request Handler. Performing a manipulation of the argument Name results in buffer overflow. The attack can be initiated remotely. The exploit is now…

πŸ“… Published: May 5, 2026, 6:30 p.m. πŸ”„ Last Modified: May 6, 2026, 5:38 p.m.

9.3

CVSS4.0

CVE-2026-7854 - D-Link DI-8100 POST Parameter url_rule.asp url_rule_asp buffer overflow

A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component POST Parameter Handler. Such manipulation leads to buffer overflow. It is possible to launch the attack remotely. The explo…

πŸ“… Published: May 5, 2026, 6:15 p.m. πŸ”„ Last Modified: May 6, 2026, 5:39 p.m.

9.3

CVSS4.0

CVE-2026-7853 - D-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made a…

πŸ“… Published: May 5, 2026, 5:45 p.m. πŸ”„ Last Modified: May 6, 2026, 5:40 p.m.
Total resulsts: 349182
Page 109 of 34,919
Β« previous page Β» next page
Filters