5.3

CVSS3.1

CVE-2026-43506 - Memory Leak Leads to Denial of Service in Prosody

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.

πŸ“… Published: May 1, 2026, 2:45 p.m. πŸ”„ Last Modified: May 1, 2026, 11 p.m.

5.3

CVSS4.0

CVE-2026-7583 - Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service

A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /src/bsf/context.c of the component BSF. This manipulation of the argument ipv6Prefix causes denial of service. It is possible to initiate the attack remotely. The exploit has been …

πŸ“… Published: May 1, 2026, 2:45 p.m. πŸ”„ Last Modified: May 1, 2026, 9:30 p.m.

6.5

CVSS3.1

CVE-2026-43505 - Unauthorized traffic relay via misconfigured mod_proxy65

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relaying of unauthenticated traffic can occur.

πŸ“… Published: May 1, 2026, 2:42 p.m. πŸ”„ Last Modified: May 1, 2026, 11 p.m.

6.5

CVSS3.1

CVE-2026-43504 - Unauthenticated XMPP Traffic Relay via Improper mod_proxy65 Access Control

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of unauthenticated traffic can occur.

πŸ“… Published: May 1, 2026, 2:40 p.m. πŸ”„ Last Modified: May 2, 2026, 7:15 a.m.

4.8

CVSS4.0

CVE-2026-7582 - AcademySoftwareFoundation OpenImageIO DDS Image ddsinput.cpp out-of-bounds write

A vulnerability was detected in AcademySoftwareFoundation OpenImageIO up to 3.2.0.1-dev. This vulnerability affects unknown code of the file src/dds.imageio/ddsinput.cpp of the component DDS Image Handler. The manipulation results in out-of-bounds write. The attack needs to be approached locally. T…

πŸ“… Published: May 1, 2026, 1:45 p.m. πŸ”„ Last Modified: May 4, 2026, 4:14 p.m.

5.3

CVSS3.1

CVE-2026-3143 - Total Upkeep <= 1.17.1 - Missing Authorization to Unauthenticated Rollback Cancellation

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unaut…

πŸ“… Published: May 1, 2026, 1:28 p.m. πŸ”„ Last Modified: May 4, 2026, 6:23 p.m.

5.3

CVSS4.0

CVE-2026-7581 - alexta69 MeTube CORS Policy main.py on_prepare cross-domain policy

A security vulnerability has been detected in alexta69 MeTube up to 2026.04.09. This affects the function on_prepare of the file app/main.py of the component CORS Policy. The manipulation leads to permissive cross-domain policy with untrusted domains. The attack is possible to be carried out remote…

πŸ“… Published: May 1, 2026, 1 p.m. πŸ”„ Last Modified: May 4, 2026, 4:07 p.m.

4.8

CVSS4.0

CVE-2026-7580 - Exiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injection

A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTool/GM.pm of the component JPEG/QuickTime/MOV/MP4. The manipulation of the argument -ee results in code injection. Attacking locally is a requirement. Upgrading to version 13.54 is…

πŸ“… Published: May 1, 2026, noon πŸ”„ Last Modified: May 3, 2026, 9:30 p.m.

6.9

CVSS4.0

CVE-2026-7579 - AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The e…

πŸ“… Published: May 1, 2026, 11:30 a.m. πŸ”„ Last Modified: May 4, 2026, 2:16 p.m.

4.3

CVSS3.1

CVE-2026-3140 - Ultimate Dashboard <= 3.8.14 - Cross-Site Request Forgery to Module Activation/Deactivation

The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.14. This is due to a flawed nonce validation conditional in the 'handle_module_actions' function. This makes it possible for unauthenticated attackers to toggle plugin m…

πŸ“… Published: May 1, 2026, 11:18 a.m. πŸ”„ Last Modified: May 4, 2026, 4:07 p.m.
Total resulsts: 349182
Page 158 of 34,919
Β« previous page Β» next page
Filters