4.9

CVSS3.1

CVE-2026-27807 - MarkUs: YAML alias (โ€˜billion laughsโ€™) DoS in config upload

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update various entities (e.g., assignment settings). These YAML files are parsed with aliases enabled. This issue has been patchโ€ฆ

๐Ÿ“… Published: March 6, 2026, 2:48 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10 a.m.

5.3

CVSS4.0

CVE-2026-3616 - DefaultFuction Jeson Customer Relationship Management System edit.php sql injection

A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modules/customers/edit.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is noโ€ฆ

๐Ÿ“… Published: March 6, 2026, 1:32 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:27 p.m.

8.6

CVSS4.0

CVE-2026-3613 - Wavlink WL-NU516U1 login.cgi sub_401A0C stack-based overflow

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly availโ€ฆ

๐Ÿ“… Published: March 6, 2026, 1:02 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 12:30 p.m.

8.6

CVSS4.0

CVE-2026-3612 - Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. This manipulation of the argument firmware_url causes command injection. It is possible to initiate the attack remotely. The exploit hโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 11:45 a.m.

5.3

CVSS4.0

CVE-2026-3610 - HSC Cybersecurity Mailinspector URL mliUserValidation.php cross site scripting

A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown functionality of the file /mailinspector/mliUserValidation.php of the component URL Handler. The manipulation of the argument error_description results in cross site scripting. The attโ€ฆ

๐Ÿ“… Published: March 6, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:27 p.m.

6.2

CVSS3.1

CVE-2025-69652 - binutils: abort in readelf via crafted ELF binary with malformed DWARF abbrev or debug information

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute pโ€ฆ

๐Ÿ“… Published: March 6, 2026, midnight ๐Ÿ”„ Last Modified: March 11, 2026, 3:49 p.m.

7.5

CVSS3.1

CVE-2025-69654 -

A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime (listโ€ฆ

๐Ÿ“… Published: March 6, 2026, midnight ๐Ÿ”„ Last Modified: March 12, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2025-70363 -

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

๐Ÿ“… Published: March 6, 2026, midnight ๐Ÿ”„ Last Modified: March 9, 2026, 7:16 p.m.

6.5

CVSS3.1

CVE-2025-69653 -

A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs interpreter using the -m option. This leads to an abort (SIGABRโ€ฆ

๐Ÿ“… Published: March 6, 2026, midnight ๐Ÿ”„ Last Modified: March 12, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2025-69650 - binutils: Binutils: Denial of Service via crafted ELF binary

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may โ€ฆ

๐Ÿ“… Published: March 6, 2026, midnight ๐Ÿ”„ Last Modified: March 19, 2026, 1:16 p.m.
Total resulsts: 349182
Page 1286 of 34,919
ยซ previous page ยป next page
Filters