8.7

CVSS4.0

CVE-2026-25048 - xgrammar: Multi-layer nesting causes DoS

xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.

πŸ“… Published: March 5, 2026, 3:34 p.m. πŸ”„ Last Modified: April 17, 2026, 12:45 p.m.

5.4

CVSS3.1

CVE-2025-64166 - Mercurius: Incorrect Content-Type parsing can lead to CSRF attack

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of the Content-Type header in requests. Specifically, requests with Content-Type values such as application/x-www-form-urlen…

πŸ“… Published: March 5, 2026, 3:31 p.m. πŸ”„ Last Modified: March 13, 2026, 6:05 p.m.

8.7

CVSS4.0

CVE-2026-30796 - RustDesk Server Pro API Requires Address Book Password in Plaintext for Sync Protocol

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source β€” API endpoint handling he…

πŸ“… Published: March 5, 2026, 3:30 p.m. πŸ”„ Last Modified: April 16, 2026, 12:30 p.m.

8.7

CVSS4.0

CVE-2026-30795 - RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routin…

πŸ“… Published: March 5, 2026, 3:27 p.m. πŸ”„ Last Modified: April 16, 2026, 12:30 p.m.

9.1

CVSS4.0

CVE-2026-30794 - RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure

Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs an…

πŸ“… Published: March 5, 2026, 3:24 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 a.m.

9.3

CVSS4.0

CVE-2026-30793 - RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/fl…

πŸ“… Published: March 5, 2026, 3:21 p.m. πŸ”„ Last Modified: April 17, 2026, 12:45 p.m.

9.1

CVSS4.0

CVE-2026-30792 - RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files…

πŸ“… Published: March 5, 2026, 3:14 p.m. πŸ”„ Last Modified: April 17, 2026, 1 p.m.

8.7

CVSS4.0

CVE-2026-30791 - RustDesk Client Accepts Pseudo-Encrypted Config Strings Without Cryptographic Validation

Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config modules) allows Retrieve Embedded Sensitive Data. This vulnerability is associated wit…

πŸ“… Published: March 5, 2026, 2:47 p.m. πŸ”„ Last Modified: April 16, 2026, 12:30 p.m.

7.8

CVSS3.1

CVE-2026-27748 - Avira Internet Security Arbitrary File Deletion via Improper Link Resolution

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point.…

πŸ“… Published: March 5, 2026, 2:15 p.m. πŸ”„ Last Modified: April 15, 2026, 10:45 p.m.

7.8

CVSS3.1

CVE-2026-27749 - Avira Internet Security System Speedup Insecure Deserialization

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without i…

πŸ“… Published: March 5, 2026, 2:15 p.m. πŸ”„ Last Modified: April 16, 2026, 4:45 a.m.
Total resulsts: 349182
Page 1301 of 34,919
Β« previous page Β» next page
Filters