9.8

CVSS3.1

CVE-2025-62373 - Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integra…

📅 Published: April 23, 2026, 2:40 p.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.

7.8

CVSS3.1

CVE-2026-34003 - Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bounds memory…

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerability. This could result in the disclosure of sensitive information or cause the server to crash, lea…

📅 Published: April 23, 2026, 2:18 p.m. 🔄 Last Modified: April 27, 2026, 9:06 a.m.

7.8

CVSS3.1

CVE-2026-34001 - Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential me…

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to the X11 server can exploit this without user interaction, leading to a server crash and potentially…

📅 Published: April 23, 2026, 2:14 p.m. 🔄 Last Modified: April 27, 2026, 9:05 a.m.

7.8

CVSS3.1

CVE-2026-33999 - Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibility map ha…

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger a buffer read overrun. This can lead to memory-safety violations and potentially a denial of service…

📅 Published: April 23, 2026, 2:11 p.m. 🔄 Last Modified: April 27, 2026, 9:05 a.m.

8.7

CVSS4.0

CVE-2026-35225 - Improper timeout handling in CODESYS EtherNetIP

An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

📅 Published: April 23, 2026, 1:54 p.m. 🔄 Last Modified: April 27, 2026, 10:30 p.m.

6.3

CVSS4.0

CVE-2026-41461 - SocialEngine <= 7.8.0 Blind SSRF via /core/link/preview

SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers ca…

📅 Published: April 23, 2026, 1:45 p.m. 🔄 Last Modified: April 27, 2026, 2:53 p.m.

9.3

CVSS4.0

CVE-2026-41460 - SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized before being incorporated into a SQL query. An unauthenticated remote attacker can exploit this vulnerab…

📅 Published: April 23, 2026, 1:44 p.m. 🔄 Last Modified: April 27, 2026, 2:54 p.m.

4.7

CVSS3.1

CVE-2025-66286 - Webkitgtk: authorization bypass through webpage::send-request signal handler

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests …

📅 Published: April 23, 2026, 12:15 p.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.

9.9

CVSS3.1

CVE-2026-39440 - WordPress FunnelFormsPro plugin <= 3.8.1 - Remote Code Execution (RCE) vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

📅 Published: April 23, 2026, 12:11 p.m. 🔄 Last Modified: April 28, 2026, 9 a.m.

5.7

CVSS3.1

CVE-2025-13763 - Libopensc: opensc: multiple uses of uninitialized variable

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present the system with specially crafted responses to the APDUs

📅 Published: April 23, 2026, 12:09 p.m. 🔄 Last Modified: April 28, 2026, 9:26 a.m.
Total resulsts: 347814
Page 167 of 34,782
« previous page » next page
Filters