9.8

CVSS3.1

CVE-2026-22891 - Heap Overflow in libbiosig Intan CLP Parsing Leading to Arbitrary Code Execution

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerabilit…

πŸ“… Published: March 3, 2026, 2:32 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 p.m.

8.1

CVSS3.1

CVE-2026-20777 - Heap Overflow in Biosig libbiosig 3.9.2 Enables Code Execution

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“… Published: March 3, 2026, 2:32 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.

3.7

CVSS3.1

CVE-2026-25674 - Potential incorrect permissions on newly created file system objects

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's t…

πŸ“… Published: March 3, 2026, 2:28 p.m. πŸ”„ Last Modified: April 17, 2026, 1:30 p.m.

7.5

CVSS3.1

CVE-2026-25673 - Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause d…

πŸ“… Published: March 3, 2026, 2:28 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 p.m.

8.5

CVSS4.0

CVE-2026-2637 -

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd.Β The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks. This issue affects iBoysoft NTFS: 8.0.0.

πŸ“… Published: March 3, 2026, 2:04 p.m. πŸ”„ Last Modified: April 27, 2026, 1:12 p.m.

6.9

CVSS4.0

CVE-2026-3344 - WatchGuard Firebox System Integrity Check Bypass

A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 p.m.

5.1

CVSS4.0

CVE-2026-3343 - WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. This vulnerability affects Fireware OS 12.7 up to and including 12.11.7…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.

8.6

CVSS4.0

CVE-2026-3342 - WatchGuard Firebox Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and in…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

2.1

CVSS4.0

CVE-2026-3351 - Authorization Bypass in LXD GET /1.0/certificates Endpoint

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

πŸ“… Published: March 3, 2026, 12:49 p.m. πŸ”„ Last Modified: April 17, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-3463 - xlnt-community xlnt Compound Document binary.hpp append heap-based overflow

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locall…

πŸ“… Published: March 3, 2026, 12:02 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.
Total resulsts: 348208
Page 1265 of 34,821
Β« previous page Β» next page
Filters