8.6

CVSS4.0

CVE-2026-29002 - CouchCMS Privilege Escalation via f_k_levels_list Parameter

CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass author…

πŸ“… Published: April 10, 2026, 3:11 p.m. πŸ”„ Last Modified: April 10, 2026, 4:20 p.m.

4.7

CVSS3.1

CVE-2026-40223 -

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

πŸ“… Published: April 10, 2026, 3:10 p.m. πŸ”„ Last Modified: April 10, 2026, 4:16 p.m.

8.8

CVSS3.1

CVE-2026-40217 -

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

πŸ“… Published: April 10, 2026, 1:43 p.m. πŸ”„ Last Modified: April 10, 2026, 1:43 p.m.

0.0

CVE-2026-6069 - CVE-2026-6069

NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity.

πŸ“… Published: April 10, 2026, 1:30 p.m. πŸ”„ Last Modified: April 10, 2026, 1:30 p.m.

6.5

CVSS3.1

CVE-2026-6068 - CVE-2026-6068

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavio…

πŸ“… Published: April 10, 2026, 1:30 p.m. πŸ”„ Last Modified: April 10, 2026, 4:16 p.m.

7.5

CVSS3.1

CVE-2026-6067 - CVE-2026-6067

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and…

πŸ“… Published: April 10, 2026, 1:30 p.m. πŸ”„ Last Modified: April 10, 2026, 4:16 p.m.

7.1

CVSS3.1

CVE-2025-58920 - WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato allows Reflected XSS.This issue affects Cerato: from n/a through 2.2.18.

πŸ“… Published: April 10, 2026, 1:25 p.m. πŸ”„ Last Modified: April 10, 2026, 1:25 p.m.

8.1

CVSS3.1

CVE-2025-58913 - WordPress VideoPro theme <= 2.3.8.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro allows PHP Local File Inclusion.This issue affects VideoPro: from n/a through 2.3.8.1.

πŸ“… Published: April 10, 2026, 1:21 p.m. πŸ”„ Last Modified: April 10, 2026, 1:21 p.m.

7.5

CVSS3.1

CVE-2025-5804 - WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User allows PHP Local File Inclusion.This issue affects Case Theme User: from n/a before 1.0.4.

πŸ“… Published: April 10, 2026, 1:19 p.m. πŸ”„ Last Modified: April 10, 2026, 1:19 p.m.

7.8

CVSS3.0

CVE-2026-33092 -

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.

πŸ“… Published: April 10, 2026, 1:17 p.m. πŸ”„ Last Modified: April 10, 2026, 1:17 p.m.
Total resulsts: 343921
Page 16 of 34,393
Β« previous page Β» next page
Filters