9.8

CVSS3.1

CVE-2026-41492 - Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in Dgraph

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker can retri…

πŸ“… Published: April 24, 2026, 6:29 p.m. πŸ”„ Last Modified: April 24, 2026, 6:29 p.m.

9.1

CVSS3.1

CVE-2026-41327 - Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack is a sing…

πŸ“… Published: April 24, 2026, 6:27 p.m. πŸ”„ Last Modified: April 24, 2026, 6:27 p.m.

9.1

CVSS3.1

CVE-2026-41328 - Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requires …

πŸ“… Published: April 24, 2026, 6:25 p.m. πŸ”„ Last Modified: April 24, 2026, 6:25 p.m.

7.5

CVSS3.1

CVE-2026-33666 - Zserio: Integer Overflow in BitStreamReader on 32-bit platforms

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), the setBitPosition() bounds check receives the overflowed value and is completely bypassed. The code then reads len bytes (512 …

πŸ“… Published: April 24, 2026, 6:21 p.m. πŸ”„ Last Modified: April 24, 2026, 6:21 p.m.

7.5

CVSS3.1

CVE-2026-33524 - Zserio: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization

Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service). This vulnerability is fixed in …

πŸ“… Published: April 24, 2026, 6:18 p.m. πŸ”„ Last Modified: April 24, 2026, 6:18 p.m.

7.5

CVSS3.1

CVE-2026-33662 - OP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From 3.8.0 to 4.10, in the function emsa_pkcs1_v1_5_encode() in core/drivers/crypto/crypto_api/acipher/rsassa.c, the amount of padding ne…

πŸ“… Published: April 24, 2026, 6:13 p.m. πŸ”„ Last Modified: April 24, 2026, 6:13 p.m.

8.1

CVSS4.0

CVE-2026-41907 - uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

πŸ“… Published: April 24, 2026, 6:09 p.m. πŸ”„ Last Modified: April 24, 2026, 6:09 p.m.

5.4

CVSS3.1

CVE-2026-42042 - Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Co…

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy no…

πŸ“… Published: April 24, 2026, 6:03 p.m. πŸ”„ Last Modified: April 24, 2026, 6:03 p.m.

6.9

CVSS4.0

CVE-2026-42039 - Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.3…

πŸ“… Published: April 24, 2026, 6:01 p.m. πŸ”„ Last Modified: April 24, 2026, 6:01 p.m.

5.3

CVSS3.1

CVE-2026-42036 - Axios: HTTP adapter streamed responses bypass maxContentLength

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vu…

πŸ“… Published: April 24, 2026, 6 p.m. πŸ”„ Last Modified: April 24, 2026, 6 p.m.
Total resulsts: 347943
Page 145 of 34,795
Β« previous page Β» next page
Filters