7.7

CVSS3.1

CVE-2026-32324 - Anviz CX7 Firmware Use of Hard-coded Cryptographic Key

Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption of MQTT traffic and potential interaction with device messaging channels at scale.

📅 Published: April 17, 2026, 7:22 p.m. 🔄 Last Modified: April 20, 2026, 7:05 p.m.

5.3

CVSS3.1

CVE-2026-35061 - Anviz Products Missing Authorization

Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication, revealing sensitive operational imagery.

📅 Published: April 17, 2026, 7:19 p.m. 🔄 Last Modified: April 20, 2026, 7:05 p.m.

5.3

CVSS3.1

CVE-2026-33093 - Anviz Products Missing Authorization

Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing camera, exposing visual information about the deployment environment.

📅 Published: April 17, 2026, 7:17 p.m. 🔄 Last Modified: April 20, 2026, 7:05 p.m.

7.5

CVSS3.1

CVE-2026-35215 - Firebird: DoS via malicious slice descriptor in slice packet

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_desc() function does not validate the length of a decoded SDL descriptor from a slice packet. A zero-length descriptor is later used to calculate the number of slice items, causin…

📅 Published: April 17, 2026, 6:59 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

7.5

CVSS3.1

CVE-2026-34232 - Firebird: DoS via `op_response` packet from client

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unau…

📅 Published: April 17, 2026, 6:52 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

7.5

CVSS3.1

CVE-2026-33337 - Firebird has a buffer overflow when parsing corrupted slice packets

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bounds, allowing a cstring longer than the allocated b…

📅 Published: April 17, 2026, 6:48 p.m. 🔄 Last Modified: April 20, 2026, 7:03 p.m.

6.9

CVSS4.0

CVE-2026-6437 - AWS EFS CSI Driver Mount Option Injection

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection. To remediate this issue, u…

📅 Published: April 17, 2026, 6:41 p.m. 🔄 Last Modified: April 20, 2026, 7:05 p.m.

8.2

CVSS3.1

CVE-2026-28224 - Firebird Null Pointer Dereference via CryptCallback causes DOS

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference a…

📅 Published: April 17, 2026, 6:38 p.m. 🔄 Last Modified: April 24, 2026, 7:45 p.m.

6

CVSS4.0

CVE-2026-28214 - Firebird server hangs when using specific clumplet on batch creation

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite loop. An authenticated user with INSERT privileges…

📅 Published: April 17, 2026, 6:35 p.m. 🔄 Last Modified: April 24, 2026, 7:47 p.m.

9.1

CVSS4.0

CVE-2026-40525 - OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI

OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or empty. Remote attackers with network access to the exposed service can invoke priv…

📅 Published: April 17, 2026, 6:19 p.m. 🔄 Last Modified: April 22, 2026, 3:45 a.m.
Total resulsts: 346583
Page 153 of 34,659
« previous page » next page
Filters