9.8

CVSS3.1

CVE-2025-70233 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:36 p.m.

8.1

CVSS3.1

CVE-2025-70614 -

OpenCode Systems OC Messaging / USSD Gateway OC Release 6.32.2 contains a broken access control vulnerability in the web-based control panel allowing authenticated low-privileged attackers to gain to access to arbitrary SMS messages via a crafted company or tenant identifier parameter.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 5:51 p.m.

9.8

CVSS3.1

CVE-2025-29165 - Privilege Escalation via /etc/shadow.sample on D-Link DIR-1253

An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: May 6, 2026, 5:58 p.m.

9.8

CVSS3.1

CVE-2025-70231 -

D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin, it enters /goform/getAuthCode but fails to filter the value of the FILECODE parameter, resulting in a path traversal vulnerability.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:37 p.m.

5.4

CVSS3.1

CVE-2026-26377 - Koha 25.11 and Earlier: Reflected XSS in News Function

Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the News function.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 10 a.m.

9.3

CVSS3.1

CVE-2025-70948 -

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 1:36 p.m.

8.8

CVSS3.1

CVE-2025-70995 - Remote Code Execution via Improper Validation of Uploaded web.config in Aranda Service Desk API

An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, wh…

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 11:30 a.m.

7.8

CVSS3.1

CVE-2025-70616 -

A stack buffer overflow vulnerability exists in the Wincor Nixdorf wnBios64.sys kernel driver (version 1.2.0.0) in the IOCTL handler for code 0x80102058. The vulnerability is caused by missing bounds checking on the user-controlled Options parameter before copying data into a 40-byte stack buffer (…

πŸ“… Published: March 5, 2026, midnight πŸ”„ Last Modified: March 10, 2026, 7:41 p.m.

8.4

CVSS4.0

CVE-2026-2836 - Cache poisoning via insecure-by-default cache key

A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host header (authority). Opera…

πŸ“… Published: March 4, 2026, 11:44 p.m. πŸ”„ Last Modified: April 16, 2026, 1:15 p.m.

9.3

CVSS4.0

CVE-2026-2835 - HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attackers…

πŸ“… Published: March 4, 2026, 11:32 p.m. πŸ”„ Last Modified: April 17, 2026, 1 p.m.
Total resulsts: 349182
Page 1336 of 34,919
Β« previous page Β» next page
Filters