4.9

CVSS3.1

CVE-2026-2376 - Mirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web int…

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by providing malicious web addresses. When the application processes these addresses, it automatically follows redirects without verifying the final destin…

📅 Published: March 3, 2026, 7:28 p.m. 🔄 Last Modified: April 16, 2026, 3 a.m.

5.2

CVSS4.0

CVE-2026-2915 - HP System Event Utility – Denial of Service

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

📅 Published: March 3, 2026, 7:25 p.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

5.3

CVSS4.0

CVE-2026-3494 - MariaDB Server Audit Plugin Comment Handling Bypass

In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the sta…

📅 Published: March 3, 2026, 6:12 p.m. 🔄 Last Modified: April 18, 2026, 10:15 a.m.

9.3

CVSS4.0

CVE-2026-3437 - Improper Restriction of Operations within the Bounds of a Memory Buffer in Portwell Engineering Too…

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vuln…

📅 Published: March 3, 2026, 5:44 p.m. 🔄 Last Modified: April 17, 2026, 1:30 p.m.

5.3

CVSS4.0

CVE-2026-0540 - DOMPurify XSS via Missing Rawtext Elements in SAFE_FOR_XML

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements (noscript, xmp, noembed, noframes, iframe) in the SAFE_FOR_XML regex. Attac…

📅 Published: March 3, 2026, 5:26 p.m. 🔄 Last Modified: April 16, 2026, 2:15 p.m.

5.1

CVSS4.0

CVE-2025-15599 - DOMPurify XSS via Textarea Rawtext Bypass in SAFE_FOR_XML

DOMPurify 3.1.3 through 3.2.6 and 2.5.3 through 2.5.8 contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting missing textarea rawtext element validation in the SAFE_FOR_XML regex. Attackers can include closing rawtext tags like </textarea> …

📅 Published: March 3, 2026, 5:26 p.m. 🔄 Last Modified: March 5, 2026, 12:36 a.m.

8.6

CVSS4.0

CVE-2026-3136 - Google Cloud Build Comment Control Bypass

An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is needed.

📅 Published: March 3, 2026, 4:22 p.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.

2.3

CVSS4.0

CVE-2026-3465 - Tuya App/SDK JSON Data Point denial of service

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The com…

📅 Published: March 3, 2026, 3:02 p.m. 🔄 Last Modified: April 22, 2026, 9:26 p.m.

8.4

CVSS4.0

CVE-2026-28518 - OpenViking .ovpack Import ZIP Slip Path Traversal

OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or dri…

📅 Published: March 3, 2026, 2:36 p.m. 🔄 Last Modified: April 17, 2026, 9:19 p.m.

6.1

CVSS3.1

CVE-2025-64736 -

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

📅 Published: March 3, 2026, 2:32 p.m. 🔄 Last Modified: March 5, 2026, 6:16 p.m.
Total resulsts: 348208
Page 1264 of 34,821
« previous page » next page
Filters