8.6

CVSS4.0

CVE-2026-3342 - WatchGuard Firebox Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and inโ€ฆ

๐Ÿ“… Published: March 3, 2026, 1:17 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

2.1

CVSS4.0

CVE-2026-3351 - Authorization Bypass in LXD GET /1.0/certificates Endpoint

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

๐Ÿ“… Published: March 3, 2026, 12:49 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 1:30 p.m.

4.8

CVSS4.0

CVE-2026-3463 - xlnt-community xlnt Compound Document binary.hpp append heap-based overflow

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locallโ€ฆ

๐Ÿ“… Published: March 3, 2026, 12:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:15 a.m.

5.3

CVSS3.1

CVE-2025-59060 - Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

๐Ÿ“… Published: March 3, 2026, 10:46 a.m. ๐Ÿ”„ Last Modified: March 5, 2026, 2:13 p.m.

9.8

CVSS3.1

CVE-2025-59059 - Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

๐Ÿ“… Published: March 3, 2026, 10:44 a.m. ๐Ÿ”„ Last Modified: March 5, 2026, 2:14 p.m.

6.3

CVSS4.0

CVE-2025-15598 - Dataease SQLBot JWT Token auth.py validateEmbedded signature verification

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiaโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:32 a.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:52 p.m.

7.2

CVSS3.1

CVE-2026-2568 - WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthentiโ€ฆ

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possibleโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:24 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:26 p.m.

9.8

CVSS3.1

CVE-2026-22886 - Default Credentials Persist in Eclipse OpenMQ TCP Management Service Allowing Remote Administration

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues tโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:18 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 2:15 p.m.

8.7

CVSS4.0

CVE-2026-1876 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet module

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. Aโ€ฆ

๐Ÿ“… Published: March 3, 2026, 7:03 a.m. ๐Ÿ”„ Last Modified: April 30, 2026, 8:40 p.m.

8.7

CVSS4.0

CVE-2026-1875 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the prodโ€ฆ

๐Ÿ“… Published: March 3, 2026, 6:54 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 8:16 a.m.
Total resulsts: 349182
Page 1363 of 34,919
ยซ previous page ยป next page
Filters