6.7

CVSS3.1

CVE-2026-26951 - Stack-Based Buffer Overflow in Dell PowerProtect Data Domain Allows Local Privileged Command Execut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a stack-based buffer overflow vulnerability. A high privileged attacker with local access could potentially exploit this vulnera…

📅 Published: April 20, 2026, 4:44 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.

6.7

CVSS3.1

CVE-2026-22761 - Command Injection in Dell PowerProtect Data Domain Enabling Remote Root Execution

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

📅 Published: April 20, 2026, 4:39 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.

6.7

CVSS3.1

CVE-2026-26942 - OS Command Injection Allowing Root Privilege Escalation in Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command exec…

📅 Published: April 20, 2026, 4:34 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.

7.2

CVSS3.1

CVE-2026-26943 - OS Command Injection in Dell PowerProtect Data Domain Allows Root Privilege Escalation

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabilit…

📅 Published: April 20, 2026, 4:28 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.

6.6

CVSS3.1

CVE-2026-28684 - python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename…

python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when…

📅 Published: April 20, 2026, 4:25 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

8.7

CVSS4.0

CVE-2026-40488 - OpenMage LTS has Customer File Upload Extension Blocklist Bypass that Leads to Remote Code Execution

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the product custom option file upload in OpenMage LTS uses an incomplete blo…

📅 Published: April 20, 2026, 4:23 p.m. 🔄 Last Modified: April 23, 2026, 5:45 p.m.

7.2

CVSS3.1

CVE-2026-24506 - OS Command Injection in Dell PowerProtect Data Domain Enables Arbitrary Root Execution

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerabilit…

📅 Published: April 20, 2026, 4:22 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.

5.3

CVSS4.0

CVE-2026-40098 - OpenMage LTS imports cross-user wishlist item via shared wishlist code, leading to private option d…

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platform with a high level of backward compatibility. Prior to version 20.17.0, the shared wishlist add-to-cart endpoint authorizes access with a public `sh…

📅 Published: April 20, 2026, 4:19 p.m. 🔄 Last Modified: April 23, 2026, 5:46 p.m.

8.7

CVSS4.0

CVE-2026-41445 - KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()

KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther*(dimReal+2)*sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc(…

📅 Published: April 20, 2026, 4:18 p.m. 🔄 Last Modified: April 22, 2026, 11:47 a.m.

7.2

CVSS3.1

CVE-2026-24505 - Improper Input Validation Allows Remote Command Execution on Dell PowerProtect Data Domain

Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

📅 Published: April 20, 2026, 4:15 p.m. 🔄 Last Modified: April 22, 2026, 3:56 a.m.
Total resulsts: 346515
Page 120 of 34,652
« previous page » next page
Filters