9.8

CVSS3.1

CVE-2025-70218 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 5:52 p.m.

7.8

CVSS3.1

CVE-2026-23231 - netfilter: nf_tables: fix use-after-free in nf_tables_addchain()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hooks. If nf_tables_register_hook() then f…

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 1:45 p.m.

7.8

CVSS3.1

CVE-2025-70341 -

Insecure permissions in App-Auto-Patch v3.4.2 create a race condition which allows attackers to write arbitrary files.

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 5, 2026, 6:19 p.m.

0.0

CVE-2026-30407 -

DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 27, 2026, 2:10 p.m.

9.8

CVSS3.1

CVE-2025-66944 -

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

πŸ“… Published: March 4, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 5:29 p.m.

10

CVSS3.1

CVE-2026-28289 - FreeScout 1.8.206 Patch Bypass for CVE-2026-27636 via Zero-Width Space Character Leads to Remote Co…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a maliciou…

πŸ“… Published: March 3, 2026, 10:59 p.m. πŸ”„ Last Modified: April 16, 2026, 2 p.m.

9.2

CVSS4.0

CVE-2026-27971 - Qwik affected by unauthenticated RCE via server$ Deserialization

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where re…

πŸ“… Published: March 3, 2026, 10:55 p.m. πŸ”„ Last Modified: April 16, 2026, 2 p.m.

7.5

CVSS3.1

CVE-2026-27932 - joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS)

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to cause a Denial of Service (DoS) via CPU exhaustion. When the library…

πŸ“… Published: March 3, 2026, 10:48 p.m. πŸ”„ Last Modified: April 17, 2026, 1:30 p.m.

8.6

CVSS4.0

CVE-2026-27905 - BentoML has an Arbitrary File Write via Symlink Path Traversal in Tar Extraction

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile() function validates that each tar member's path is within the destination directory, but for symlink members it only validates the symlink's own path…

πŸ“… Published: March 3, 2026, 10:45 p.m. πŸ”„ Last Modified: April 16, 2026, 2 p.m.

8.4

CVSS4.0

CVE-2026-27622 - OpenEXR CompositeDeepScanLine integer-overflow leads to heap OOB write

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across man…

πŸ“… Published: March 3, 2026, 10:42 p.m. πŸ”„ Last Modified: April 16, 2026, 5:45 a.m.
Total resulsts: 349182
Page 1356 of 34,919
Β« previous page Β» next page
Filters