8.1

CVSS3.1

CVE-2026-24881 - GnuPG: GnuPG: Remote code execution and denial of service via crafted CMS EnvelopedData message

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily be leveraged for denial of service; however, there is also memory corruption that cโ€ฆ

๐Ÿ“… Published: Jan. 27, 2026, 6:36 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2 a.m.

6

CVSS4.0

CVE-2026-23892 - OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character based comparison that short-circuits on the firsโ€ฆ

๐Ÿ“… Published: Jan. 27, 2026, 6:35 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2 a.m.

7.4

CVSS3.1

CVE-2026-22264 - Suricata detect/alert: heap-use-after-free on alert queue expansion

Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free condition when generating excessive amounts of alerts for a single packet. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not run untrusteโ€ฆ

๐Ÿ“… Published: Jan. 27, 2026, 6:33 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2 a.m.

6.4

CVSS3.1

CVE-2026-0746 - AI Engine <= 3.3.2 - Authenticated (Subscriber+) Server-Side Request Forgery

The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the 'get_audio' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originatiโ€ฆ

๐Ÿ“… Published: Jan. 27, 2026, 6:27 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2026-22263 - Suricata http1: quadratic complexity in headers parsing over multiple packets

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packets. Version 8.0.3 patches the issue. No known workarounds are available.

๐Ÿ“… Published: Jan. 27, 2026, 6:27 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 p.m.

5.9

CVSS3.1

CVE-2026-22262 - Suricata datasets: stack overflow when saving a set

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use โ€ฆ

๐Ÿ“… Published: Jan. 27, 2026, 6:18 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 7 p.m.

3.7

CVSS3.1

CVE-2026-22261 - Suricata eve/alert: http1 xff handling can lead to denial of service

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to severe slowdowns. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, disable XFF support in the eve configuratโ€ฆ

๐Ÿ“… Published: Jan. 27, 2026, 6:10 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:15 a.m.

7.5

CVSS3.1

CVE-2026-23593 - Unauthenticated Limited File Read allows Data Exposure in Web Interface

A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.

๐Ÿ“… Published: Jan. 27, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:15 a.m.

7.8

CVSS3.1

CVE-2025-33234 -

NVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

๐Ÿ“… Published: Jan. 27, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-23592 - Insecure File Handling allows Remote Code Execution in Backup Functionality

Insecure file operations in HPE Aruba Networking Fabric Composerรขโ‚ฌโ„ขs backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

๐Ÿ“… Published: Jan. 27, 2026, 5:57 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:15 a.m.
Total resulsts: 347066
Page 1715 of 34,707
ยซ previous page ยป next page
Filters