4.3

CVSS3.1

CVE-2026-41285 - Infinite Loop in OpenBSD SLAACD and RAD Daemons Due to Zero-Length ICMPv6 ND Option

In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expression with no preceding check for whether nd_opt_len is zero.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 6:59 p.m.

6.5

CVSS3.1

CVE-2026-29647 - OpenXiangShan NEMU Cross-Context IMSIC State Leakage

In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabling cross-context information leakage or disruption of interrupt handling.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 7:45 a.m.

9.4

CVSS3.1

CVE-2026-39109 -

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 12:15 a.m.

6.5

CVSS3.1

CVE-2025-66954 - Unauthenticated Username Enumeration via /nasapi Endpoint in Buffalo Link Station Firmware 1.85-0.01

A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 4 p.m.

9.8

CVSS3.1

CVE-2026-29646 - Privilege and Virtualization Isolation Breach in OpenXiangShan NEMU

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation an…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 8:15 a.m.

9.9

CVSS3.1

CVE-2026-30269 - Doorman Improper Access Control Allows Privilege Escalation

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update model without a manage_users permission check for self-updates, enabling privi…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 3:45 a.m.

6.6

CVSS3.1

CVE-2026-31429 - net: skb: fix cross-cache free of KFENCE-allocated skb head

In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated skb head SKB_SMALL_HEAD_CACHE_SIZE is intentionally set to a non-power-of-2 value (e.g. 704 on x86_64) to avoid collisions with generic kmalloc bucket sizes. This ensures that sk…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:17 p.m.

7.1

CVSS3.1

CVE-2026-29643 - Improper Exception Handling in XiangShan CSR Subsystem Allows Local Denial of Service

XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) contains an improper exceptional-condition handling flaw in its CSR subsystem (NewCSR). On affected versions, certain sequences of CSR operations targeting non-existent/custom CSR …

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 6 a.m.

8.2

CVSS3.1

CVE-2026-39110 - Unauthenticated SQL Injection in Forgot Password Page of Apartment Visitors Management System

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve se…

πŸ“… Published: April 20, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 8:45 p.m.

5.3

CVSS4.0

CVE-2026-6586 - TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization

A vulnerability was identified in TransformerOptimus SuperAGI up to 0.0.14. Impacted is the function get_budget/update_budget of the file superagi/controllers/budget.py of the component Budget Endpoint. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. T…

πŸ“… Published: April 19, 2026, 11:45 p.m. πŸ”„ Last Modified: April 22, 2026, 8:22 p.m.
Total resulsts: 346624
Page 143 of 34,663
Β« previous page Β» next page
Filters