8.6

CVSS3.1

CVE-2026-26938 - Improper Neutralization of Special Elements Used in a Template Engine in Kibana Workflows Leading t…

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an aut…

📅 Published: Feb. 26, 2026, 5:56 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

6.5

CVSS3.1

CVE-2026-26937 - Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

📅 Published: Feb. 26, 2026, 5:51 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

6.3

CVSS4.0

CVE-2026-26227 - VLC for Android < 3.7.0 Remote Access OTP Authentication Bypass

VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature due to missing or insufficient rate limiting on one-time password (OTP) verification. The Remote Access Server uses a 4-digit OTP and does not enforce effective throttling or lockou…

📅 Published: Feb. 26, 2026, 5:37 p.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

7.2

CVSS4.0

CVE-2026-23750 - Golioth Pouch < [INSERT FIXED VERSION] BLE GATT Heap-based Buffer Overflow

Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_SERVER_CERT_MAX_LEN when receiving the first fragment, then appends subsequent fragments using memcp…

📅 Published: Feb. 26, 2026, 5:33 p.m. 🔄 Last Modified: April 16, 2026, 6:15 a.m.

2.1

CVSS4.0

CVE-2026-23749 - Golioth Firmware SDK < 0.22.0 Blockwise Transfer Path Out-of-Bounds Read

Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to improper null termination of a blockwise transfer path. blockwise_transfer_init() accepts a path whose length equals CONFIG_GOLIOTH_COAP_MAX_PATH_LEN and copies it using strncpy() wit…

📅 Published: Feb. 26, 2026, 5:32 p.m. 🔄 Last Modified: April 16, 2026, 6:15 a.m.

6.3

CVSS4.0

CVE-2026-23748 - Golioth Firmware SDK < 0.22.0 LightDB State Out-of-Bounds Read

Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB State string parsing. When processing a string payload, a payload_size value less than 2 can cause a size_t underflow when computing the number of bytes to copy (nbytes). The subs…

📅 Published: Feb. 26, 2026, 5:31 p.m. 🔄 Last Modified: April 16, 2026, 6:15 a.m.

6.3

CVSS4.0

CVE-2026-23747 - Golioth Firmware SDK < 0.22.0 Payload Utils Stack-based Buffer Overflow

Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in Payload Utils. The golioth_payload_as_int() and golioth_payload_as_float() helpers copy network-supplied payload data into fixed-size stack buffers using memcpy() with a length der…

📅 Published: Feb. 26, 2026, 5:30 p.m. 🔄 Last Modified: April 16, 2026, 6:15 a.m.

4.9

CVSS3.1

CVE-2026-26936 - Inefficient Regular Expression Complexity in Kibana Leading to Denial of Service

Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial of Service via Regular Expression Exponential Blowup (CAPEC-492).

📅 Published: Feb. 26, 2026, 5:07 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

6.5

CVSS3.1

CVE-2026-26935 - Improper Input Validation in Kibana Leading to Denial of Service

Improper Input Validation (CWE-20) in the internal Content Connectors search endpoint in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

📅 Published: Feb. 26, 2026, 5:05 p.m. 🔄 Last Modified: April 18, 2026, 10:30 a.m.

6.5

CVSS3.1

CVE-2026-26934 - Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service

Improper Validation of Specified Quantity in Input (CWE-1284) in Kibana can allow an authenticated attacker with view-only privileges to cause a Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted, malformed payload causing excessive resource consumpt…

📅 Published: Feb. 26, 2026, 5:03 p.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.
Total resulsts: 349182
Page 1422 of 34,919
« previous page » next page
Filters