9.4

CVSS4.0

CVE-2026-42810 - Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table nam…

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions. In S3 IAM policy matching, `*` is …

πŸ“… Published: May 4, 2026, 4:48 p.m. πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

8.1

CVSS3.1

CVE-2026-42075 - Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary locations on the filesystem. The --out= flag accepts user-provided paths without validation, enabli…

πŸ“… Published: May 4, 2026, 4:47 p.m. πŸ”„ Last Modified: May 4, 2026, 7:44 p.m.

9.6

CVSS3.1

CVE-2026-25293 - Incorrect authorization in PLC FW

Buffer overflow due to incorrect authorization in PLC FW

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:01 p.m.

5.5

CVSS3.1

CVE-2026-25266 - Exposed dangerous function in windows host

Memory corruption while processing IOCTL command when device is in power-save state.

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:02 p.m.

7.8

CVSS3.1

CVE-2026-24082 - Use After Free in Automotive GPU

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:02 p.m.

7.8

CVSS3.1

CVE-2025-47408 - Untrusted Pointer Dereference in Power Optimization Firmware

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:03 p.m.

7.8

CVSS3.1

CVE-2025-47407 - Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:02 p.m.

6.1

CVSS3.1

CVE-2025-47406 - Buffer Over-read in DSP Service

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:02 p.m.

9.8

CVSS3.1

CVE-2026-42027 - Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description:Β  The ExtensionLoader.instantiateExtension(Class, String)Β method loads a class by its fully-qualified name via Class.forName()Β and invokes its n…

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6 p.m.

7.8

CVSS3.1

CVE-2025-47405 - Untrusted Pointer Dereference in Camera

Memory corruption when processing camera sensor input/output control codes with invalid output buffers.

πŸ“… Published: May 4, 2026, 4:43 p.m. πŸ”„ Last Modified: May 6, 2026, 6:03 p.m.
Total resulsts: 349182
Page 131 of 34,919
Β« previous page Β» next page
Filters