3.7

CVSS3.1

CVE-2026-40969 - Spring gRPC AuthenticationException message reflected to remote client

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0…

πŸ“… Published: April 28, 2026, 2:54 p.m. πŸ”„ Last Modified: April 30, 2026, 1:24 p.m.

8.7

CVSS4.0

CVE-2026-7288 - D-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow

A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to…

πŸ“… Published: April 28, 2026, 2:46 p.m. πŸ”„ Last Modified: April 30, 2026, 1:27 p.m.

5.1

CVSS4.0

CVE-2026-7283 - SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection

A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expired. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit ha…

πŸ“… Published: April 28, 2026, 2:15 p.m. πŸ”„ Last Modified: April 28, 2026, 4:30 p.m.

2.1

CVSS4.0

CVE-2026-40556 - Insecure Directory Permissions in GNU nano Leading to Privilege Abuse

GNU nano creates the user’s ~/.local directory with overly permissive permissions when the directory does not exist yet. On first use of features requiring Cross-Desktop Group (XDG) data storage, nano explicitly requests directory mode 0777, making the directory world‑writable in environments where…

πŸ“… Published: April 28, 2026, 1:54 p.m. πŸ”„ Last Modified: April 28, 2026, 1:54 p.m.

9.6

CVSS3.1

CVE-2026-7321 - Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 5:54 p.m.

7.3

CVSS3.1

CVE-2026-7324 - Memory safety bugs fixed in Thunderbird 150.0.1

Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1 and Thunderbird 150.0.1.

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 3:27 p.m.

7.3

CVSS3.1

CVE-2026-7323 - Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR …

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: April 30, 2026, 6:38 p.m.

7.3

CVSS3.1

CVE-2026-7322 - Memory safety bugs fixed in Thunderbird ESR 140.10.1 and Thunderbird 150.0.1

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR …

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 12:30 p.m.

7.5

CVSS3.1

CVE-2026-7320 - Information disclosure due to incorrect boundary conditions in the Audio/Video component

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

πŸ“… Published: April 28, 2026, 1:49 p.m. πŸ”„ Last Modified: May 1, 2026, 12:32 p.m.

9.2

CVSS4.0

CVE-2026-27760 - OpenCATS PHP Code Injection via installer AJAX endpoint

OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter. Attackers can break out of the define() string cont…

πŸ“… Published: April 28, 2026, 1:43 p.m. πŸ”„ Last Modified: April 28, 2026, 4 p.m.
Total resulsts: 348389
Page 141 of 34,839
Β« previous page Β» next page
Filters