5.3

CVSS4.0

CVE-2026-6729 - HKUDS OpenHarness Session Key Collision Privilege Escalation

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exploiting a shared ohmo session key that lacks sender identity verification. Attackers can reuse anoth…

📅 Published: April 20, 2026, 10:01 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

2.3

CVSS4.0

CVE-2026-0930 - Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resize

Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory to the pseudo-console output.

📅 Published: April 20, 2026, 9:28 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

2.3

CVSS4.0

CVE-2026-22051 - Authenticated Low‑Privilege Information Disclosure via Unrestricted Metrics Queries in NetApp Stora…

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacker with low privileges to run arbitrary metrics queries, revealing metric results that they do not ha…

📅 Published: April 20, 2026, 9:27 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

9.8

CVSS3.1

CVE-2026-5450 - scanf %mc off-by-one heap buffer overflow

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

📅 Published: April 20, 2026, 8:55 p.m. 🔄 Last Modified: April 23, 2026, 3:33 p.m.

7.5

CVSS3.1

CVE-2026-5928 - Static buffer overflow in deprecated nis_local_principal

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially re…

📅 Published: April 20, 2026, 8:37 p.m. 🔄 Last Modified: April 23, 2026, 3:33 p.m.

8.2

CVSS3.1

CVE-2026-5358 - glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal funct…

REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API provisional and unused. Secondly it has been discovered that the NIS+ cold start cache (/var/nis/N…

📅 Published: April 20, 2026, 8:37 p.m. 🔄 Last Modified: April 22, 2026, 2:17 p.m.

7.5

CVSS3.1

CVE-2026-33626 - LMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating…

📅 Published: April 20, 2026, 8:29 p.m. 🔄 Last Modified: April 23, 2026, 1:39 p.m.

6.4

CVSS3.1

CVE-2026-4852 - Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stor…

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible fo…

📅 Published: April 20, 2026, 8:26 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

7.7

CVSS4.0

CVE-2026-33432 - Roxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication Bypass

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without esc…

📅 Published: April 20, 2026, 8:26 p.m. 🔄 Last Modified: April 21, 2026, 6:16 p.m.

5.7

CVSS4.0

CVE-2026-33431 - Roxy-WI Vulnerable to Authenticated Arbitrary File Read via Path Traversal in Config Version Viewer

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path to construct a local file path, which is subsequently opened…

📅 Published: April 20, 2026, 8:24 p.m. 🔄 Last Modified: April 20, 2026, 8:24 p.m.
Total resulsts: 346442
Page 110 of 34,645
« previous page » next page
Filters