5.4

CVSS3.1

CVE-2025-63260 -

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

5.4

CVSS3.1

CVE-2026-33372 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request body instead of requiring them through the expec…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

7.8

CVSS3.1

CVE-2025-63261 -

AWStats 8.0 is vulnerable to Command Injection via the open function

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

4.3

CVSS3.1

CVE-2026-30580 -

File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 3:16 p.m.

4.3

CVSS3.1

CVE-2026-33371 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An authenticated attacker can submit crafted XML data that is processed by an XML pa…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

7.5

CVSS3.1

CVE-2025-46597 -

Bitcoin Core 0.13.0 through 29.x has an integer overflow.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

6.1

CVSS3.1

CVE-2026-33368 -

Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Classic Webmail REST interface (/h/rest). The application fails to properly sanitize user-supplied input, allowing an unauthenticated attacker to inject malicious JavaScript into a cr…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.

4.7

CVSS3.1

CVE-2026-23275 - io_uring: ensure ctx->rings is stable for task work flags manipulation

In the Linux kernel, the following vulnerability has been resolved: io_uring: ensure ctx->rings is stable for task work flags manipulation If DEFER_TASKRUN | SETUP_TASKRUN is used and task work is added while the ring is being resized, it's possible for the OR'ing of IORING_SQ_TASKRUN to happen i…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 20, 2026, 4:27 p.m.

9.1

CVSS3.1

CVE-2026-23537 - feast: Unauthenticated Arbitrary File Write

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling a…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:35 a.m.

4.3

CVSS3.1

CVE-2026-33369 -

Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a FolderAction operation. The application fails to properly sanitize user-supplied input before incorporating it into an LDAP search filter. An authenticated attacker can exploit thi…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 23, 2026, 2:16 p.m.
Total resulsts: 340043
Page 121 of 34,005
Β« previous page Β» next page
Filters