8.4

CVSS3.1

CVE-2026-40706 - NTFS-3G SUID-root Heap Buffer Overflow Enables Privilege Escalation

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when p…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

4.9

CVSS3.1

CVE-2026-35239 - mysql: DML unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL S…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:08 p.m.

4.9

CVSS3.1

CVE-2026-22004 - mysql: InnoDB unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:03 p.m.

6.5

CVSS3.1

CVE-2026-34308 - mysql: JSON unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL S…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:10 p.m.

7.3

CVSS3.1

CVE-2026-38834 -

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.1

CVSS3.1

CVE-2026-31013 -

Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbi…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:24 p.m.

6.5

CVSS3.1

CVE-2026-30452 - Authenticated Users Can Bypass Access Control to Alter Higher-Privilege Articles in Textpattern CMS…

Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher privileges. By manipulating the article ID parameter during the duplicate-and-save workflow in text…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

6.9

CVSS3.1

CVE-2026-41527 - Local Privilege Escalation via KUniqueService in KDE Kleopatra

KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

4.9

CVSS3.1

CVE-2026-35240 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise M…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:08 p.m.

4.9

CVSS3.1

CVE-2026-35237 - mysql: InnoDB unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:09 p.m.
Total resulsts: 346906
Page 152 of 34,691
Β« previous page Β» next page
Filters