8.4

CVSS3.1

CVE-2026-40706 - NTFS-3G SUID-root Heap Buffer Overflow Enables Privilege Escalation

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when p…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

6.5

CVSS3.1

CVE-2026-34303 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise My…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:09 p.m.

6.9

CVSS3.1

CVE-2026-41527 - Local Privilege Escalation via KUniqueService in KDE Kleopatra

KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

4.9

CVSS3.1

CVE-2026-22005 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise M…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:03 p.m.

7.3

CVSS3.1

CVE-2026-38834 -

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.3

CVSS3.1

CVE-2026-31014 - Cross‑Site Request Forgery Enables Unauthorized User Account Modification

Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing requests without requiring a CSRF token or equivalent protection. The endpoint accepts application/x-www-form-urlencoded requests, and an originally POST-b…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:21 p.m.

4.9

CVSS3.1

CVE-2026-35239 - mysql: DML unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL S…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:08 p.m.

4.9

CVSS3.1

CVE-2026-34278 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attac…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:05 p.m.

6.1

CVSS3.1

CVE-2026-31013 -

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbi…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:24 p.m.

7.2

CVSS3.1

CVE-2026-37748 -

Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without any MIME type, extension, or content validation, allowing an authenticated admin to upload a PHP websh…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 4:02 p.m.
Total resulsts: 346616
Page 123 of 34,662
Β« previous page Β» next page
Filters