0.0

CVE-2026-39112 -

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisito…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 20, 2026, 5:20 p.m.

6.6

CVSS3.1

CVE-2026-31430 - X.509: Fix out-of-bounds access when parsing extensions

In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extensions Leo reports an out-of-bounds access when parsing a certificate with empty Basic Constraints or Key Usage extension because the first byte of the extension is read before che…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 23, 2026, 4:17 p.m.

8.2

CVSS3.1

CVE-2026-39110 - Unauthenticated SQL Injection in Forgot Password Page of Apartment Visitors Management System

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve se…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 20, 2026, 8:45 p.m.

6.6

CVSS3.1

CVE-2026-31429 - net: skb: fix cross-cache free of KFENCE-allocated skb head

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 value (e.g. 704 on x86_64) to avoid collisions with generic kmalloc bucket sizes. This ensures that sk…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 23, 2026, 4:17 p.m.

7.1

CVSS3.1

CVE-2026-29643 - Improper Exception Handling in XiangShan CSR Subsystem Allows Local Denial of Service

XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) contains an improper exceptional-condition handling flaw in its CSR subsystem (NewCSR). On affected versions, certain sequences of CSR operations targeting non-existent/custom CSR …

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 22, 2026, 6 a.m.

7.8

CVSS3.1

CVE-2026-29642 - Privilege Escalation via Status Register Tampering on XiangShan RISC‑V Processors

A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvcfg (e.g., csrrs in M-mode). On affected XiangShan versions (commit aecf601e803bfd2371667a3fb60bfcd83c333027, 2024-11-19), these menvcfg accesses can unexpecte…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 22, 2026, 7:45 a.m.

5.3

CVSS3.1

CVE-2026-26399 - Stack‑Use‑After‑Return in Arduino_Core_STM32 Causes Memory Corruption

A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function allocates a TIM_HandleTypeDef structure on the stack and passes its address to HAL initialization routines, where it is stored in a global timer handle registry. After the functi…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 22, 2026, 9:16 p.m.

7.5

CVSS3.1

CVE-2026-29645 -

NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly validate the funct3 field when decoding vsetvli/vsetivli/vsetvl, allowing certain invalid OP-V instruction encodings to be misinterpreted …

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 24, 2026, 7:25 p.m.

9.8

CVSS3.1

CVE-2026-29649 -

NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode write to menvcfg can implicitly modify the hypervisor's environment configuration. This can lead to i…

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 24, 2026, 7:23 p.m.

8.8

CVSS3.1

CVE-2026-29648 - Privilege Escalation via Improper CSRs Access in OpenXiangShan NEMU

In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privileged code may read or write these CSRs without the required exception, potentially bypassing intended state-enable based isolation controls …

📅 Published: April 20, 2026, midnight 🔄 Last Modified: April 22, 2026, 7:45 a.m.
Total resulsts: 346622
Page 142 of 34,663
« previous page » next page
Filters