7.5

CVSS3.1

CVE-2026-33870 - Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix โ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:54 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.

8.7

CVSS4.0

CVE-2026-4975 - Tenda AC15 POST Request setcfm formSetCfm memory corruption

A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.

8.7

CVSS4.0

CVE-2026-4974 - Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to launch the attack rโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.

5.1

CVSS4.0

CVE-2026-4973 - SourceCodester Online Quiz System add-question.php cross site scripting

A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument quiz_question results in cross site scripting. It is possible to initiate the attaโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 11:17 p.m.

4.8

CVSS3.1

CVE-2026-33869 - Mastodon has a denial of service for quote authorization

Mastodon is a free, open-source social network server based on ActivityPub. In versions on the 4.5.x branch prior to 4.5.8 and on the 4.4.x branch prior to 4.4.15, an attacker that knows of a quote before it has reached a server can prevent it from being correctly processed on that server. The vulnโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:52 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:29 p.m.

4.3

CVSS3.1

CVE-2026-33868 - Mastodon has a GET-Based Open Redirect via '/web/%2F<domain>'

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21, an unauthenticated Open Redirect vulnerability (CWE-601) exists in the `/web/*` route due to improper handling of URL-encoded path segments. An attacker can craft a specially encโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:50 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.

8.9

CVSS4.0

CVE-2026-33765 - Pi-hole Web Interface has a Command Injection Vulnerability

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme'] parameteโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:46 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.

5.7

CVSS3.1

CVE-2026-33739 - FOG has Stored XSS in Multiple Management Pages

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing tables on multiple management pages (Host, Storage, Group, Image, Printer, Snapin) are vulnerable to Stored Cross-Site Scripting (XSS), due to insufficient server-side parameter sanโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:45 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:29 p.m.

8.9

CVSS4.0

CVE-2026-33654 - Zero-Click Indirect Prompt Injection and Authentication Bypass via Email Polling

nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module (`nanobot/channels/email.py`), allowing a remote, unauthenticated attacker to execute arbitrary LLM instructions (and subsequently, system tools) withโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:43 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.

9.7

CVSS3.1

CVE-2026-34205 - Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Moโ€ฆ

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuratioโ€ฆ

๐Ÿ“… Published: March 27, 2026, 7:41 p.m. ๐Ÿ”„ Last Modified: March 27, 2026, 8:16 p.m.
Total resulsts: 341042
Page 14 of 34,105
ยซ previous page ยป next page
Filters