5.8

CVSS3.1

CVE-2024-43035 -

Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voice/src/utils.ts. NOTE: serveFiles exists in 0.5.5 but not in the next release, 0.6.1.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 9, 2026, 1:36 p.m.

7.5

CVSS3.1

CVE-2025-45691 - ragas: arbitrary file read via improper URL validation in multimodal inputs

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 10, 2026, 7:38 p.m.

7.5

CVSS3.1

CVE-2025-69534 - python-markdown: denial of service via malformed HTML-like sequences

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown mโ€ฆ

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 1:25 a.m.

8.1

CVSS3.1

CVE-2026-26417 -

A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to reset passwords of arbitrary user accounts via crafted requests.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: April 17, 2026, 1 p.m.

7.5

CVSS3.1

CVE-2026-26418 - Unauthenticated Access in Cognix Recon Client Web API Allows Remote Functionality Exfiltration

Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows remote attackers to access application functionality without restriction via the network.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 1:15 p.m.

7.5

CVSS3.1

CVE-2025-70949 -

An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 9, 2026, 1:36 p.m.

8.8

CVSS3.1

CVE-2026-26416 - Authorization bypass in TCS Cognix Recon Client enabling privilege escalation

An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across role boundaries via crafted requests.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: April 17, 2026, 1 p.m.

9.8

CVSS3.1

CVE-2025-70229 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 6, 2026, 5:38 p.m.

9.8

CVSS3.1

CVE-2025-70232 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 6, 2026, 5:36 p.m.

9.8

CVSS3.1

CVE-2025-70230 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.

๐Ÿ“… Published: March 5, 2026, midnight ๐Ÿ”„ Last Modified: March 6, 2026, 5:37 p.m.
Total resulsts: 349182
Page 1335 of 34,919
ยซ previous page ยป next page
Filters