6.5

CVSS3.1

CVE-2026-6068 - CVE-2026-6068

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavio…

πŸ“… Published: April 10, 2026, 1:30 p.m. πŸ”„ Last Modified: April 10, 2026, 4:16 p.m.

7.5

CVSS3.1

CVE-2026-6067 - CVE-2026-6067

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and…

πŸ“… Published: April 10, 2026, 1:30 p.m. πŸ”„ Last Modified: April 10, 2026, 4:16 p.m.

7.1

CVSS3.1

CVE-2025-58920 - WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato allows Reflected XSS.This issue affects Cerato: from n/a through 2.2.18.

πŸ“… Published: April 10, 2026, 1:25 p.m. πŸ”„ Last Modified: April 10, 2026, 1:25 p.m.

8.1

CVSS3.1

CVE-2025-58913 - WordPress VideoPro theme <= 2.3.8.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro allows PHP Local File Inclusion.This issue affects VideoPro: from n/a through 2.3.8.1.

πŸ“… Published: April 10, 2026, 1:21 p.m. πŸ”„ Last Modified: April 10, 2026, 1:21 p.m.

7.5

CVSS3.1

CVE-2025-5804 - WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User allows PHP Local File Inclusion.This issue affects Case Theme User: from n/a before 1.0.4.

πŸ“… Published: April 10, 2026, 1:19 p.m. πŸ”„ Last Modified: April 10, 2026, 1:19 p.m.

7.8

CVSS3.0

CVE-2026-33092 -

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.

πŸ“… Published: April 10, 2026, 1:17 p.m. πŸ”„ Last Modified: April 10, 2026, 1:17 p.m.

9.9

CVSS3.1

CVE-2026-5412 - Juju CloudSpec API could leak senstive information

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to bootstrap the controller. This allows a low-privileged user to access sensitive credentials. This iss…

πŸ“… Published: April 10, 2026, 12:22 p.m. πŸ”„ Last Modified: April 10, 2026, 2:40 p.m.

6.1

CVSS4.0

CVE-2026-5774 - Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map

Improper synchronization of the userTokens map in the API server in Canonical JujuΒ 4.0.5,Β 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

πŸ“… Published: April 10, 2026, 12:10 p.m. πŸ”„ Last Modified: April 10, 2026, 2:40 p.m.

8.7

CVSS4.0

CVE-2026-5777 - Security Misconfiguration Vulnerability in Atom 3x Projector

This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication or access controls. An unauthenticated attacker on the same network can exploit this vulnerability to obtain root-level access, leading…

πŸ“… Published: April 10, 2026, 11:40 a.m. πŸ”„ Last Modified: April 10, 2026, 11:40 a.m.

7.5

CVSS3.1

CVE-2026-39304 - Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect han…

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes t…

πŸ“… Published: April 10, 2026, 10:54 a.m. πŸ”„ Last Modified: April 10, 2026, 3:16 p.m.
Total resulsts: 343887
Page 13 of 34,389
Β« previous page Β» next page
Filters