5.5

CVSS3.1

CVE-2026-23276 - net: add xmit recursion limit to tunnel xmit functions

In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functions Tunnel xmit functions (iptunnel_xmit, ip6tunnel_xmit) lack their own recursion limit. When a bond device in broadcast mode has GRE tap interfaces as slaves, and those GRE tun…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 10:20 a.m.

5.5

CVSS3.1

CVE-2026-23271 - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only pre…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 10:20 a.m.

6.1

CVSS3.1

CVE-2026-29828 -

DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

6.1

CVSS3.1

CVE-2026-33370 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Zimbra Briefcase feature due to insufficient sanitization of specific uploaded file types. When a user opens a publicly shared Briefcase file containing malicious scr…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

6.5

CVSS3.1

CVE-2026-30579 -

File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

7.2

CVSS3.1

CVE-2025-55988 -

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

9.8

CVSS3.1

CVE-2024-44722 -

SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

5.4

CVSS3.1

CVE-2025-63260 -

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

5.4

CVSS3.1

CVE-2026-33372 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request body instead of requiring them through the expec…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

7.8

CVSS3.1

CVE-2025-63261 -

AWStats 8.0 is vulnerable to Command Injection via the open function

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.
Total resulsts: 340040
Page 120 of 34,004
Β« previous page Β» next page
Filters