9.9

CVSS4.0

CVE-2026-29200 - Critical IDOR in Comet Backup Enables Tenant Admin Impersonation

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user account of other tenants on the same server via a vulnerable API call.

๐Ÿ“… Published: May 4, 2026, 5:42 a.m. ๐Ÿ”„ Last Modified: May 4, 2026, 7:44 p.m.

8.1

CVSS3.1

CVE-2026-29199 -

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host header which is used to generate the password reset link URL. An attacker who can manipulate the Hosโ€ฆ

๐Ÿ“… Published: May 4, 2026, 5:42 a.m. ๐Ÿ”„ Last Modified: May 4, 2026, 10 p.m.

6.5

CVSS3.1

CVE-2026-20450 -

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch Iโ€ฆ

๐Ÿ“… Published: May 4, 2026, 5:41 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 12:42 p.m.

6.5

CVSS3.1

CVE-2026-20449 -

In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:โ€ฆ

๐Ÿ“… Published: May 4, 2026, 5:41 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 12:43 p.m.

6.7

CVSS3.1

CVE-2026-20448 -

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.

๐Ÿ“… Published: May 4, 2026, 5:41 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 12:43 p.m.

6.7

CVSS3.1

CVE-2026-20447 -

In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296.

๐Ÿ“… Published: May 4, 2026, 5:41 a.m. ๐Ÿ”„ Last Modified: May 7, 2026, 12:43 p.m.

3.7

CVSS3.1

CVE-2026-43859 - mutt: Mutt: Low integrity impact in IMAP authentication due to cryptographic digest mishandling

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

๐Ÿ“… Published: May 4, 2026, 5:41 a.m. ๐Ÿ”„ Last Modified: May 5, 2026, 7:44 p.m.

6.9

CVSS4.0

CVE-2026-7736 - osrg GoBGP mrt.go parseRibEntry integer underflow

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this iโ€ฆ

๐Ÿ“… Published: May 4, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: May 4, 2026, 10:37 a.m.

6.9

CVSS4.0

CVE-2026-7735 - osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow

A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. Upgrading tโ€ฆ

๐Ÿ“… Published: May 4, 2026, 5:15 a.m. ๐Ÿ”„ Last Modified: May 4, 2026, 12:49 p.m.

6.9

CVSS4.0

CVE-2026-7734 - osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from rโ€ฆ

๐Ÿ“… Published: May 4, 2026, 5 a.m. ๐Ÿ”„ Last Modified: May 4, 2026, 5:49 p.m.
Total resulsts: 349182
Page 138 of 34,919
ยซ previous page ยป next page
Filters