8.1

CVSS3.1

CVE-2026-24450 - LibRaw: LibRaw: Arbitrary code execution via a specially crafted malicious file

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

📅 Published: April 7, 2026, 1:49 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

8.1

CVSS3.1

CVE-2026-20884 -

An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

📅 Published: April 7, 2026, 1:49 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

8.7

CVSS3.1

CVE-2026-35554 - Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Conditi…

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is pr…

📅 Published: April 7, 2026, 1:07 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-33866 - Authorization Bypass in MLflow AJAX Endpoint

MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to acc…

📅 Published: April 7, 2026, 12:57 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.1

CVSS4.0

CVE-2026-33865 - Stored XSS via unsafe YAML parsing in MLflow

MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows actio…

📅 Published: April 7, 2026, 12:57 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

9.3

CVSS4.0

CVE-2026-22679 - Weaver E-cology 10.0 Unauthenticated RCE via dubboApi Debug Endpoint

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpoint that allows attackers to execute arbitrary commands by invoking exposed debug functionality. Attackers can craft PO…

📅 Published: April 7, 2026, 12:51 p.m. 🔄 Last Modified: April 7, 2026, 1:31 p.m.

9.3

CVSS4.0

CVE-2021-4473 - Tianxin Internet Behavior Management System Command Injection via toQuery.php

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClass parameter containing shell metacharacters and output redirection. Attackers c…

📅 Published: April 7, 2026, 12:50 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

9.8

CVSS3.1

CVE-2026-5735 - Memory safety bugs fixed in Firefox 149.0.2 and Thunderbird 149.0.2

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149.0.2 and Thunderbird < 149.0.2.

📅 Published: April 7, 2026, 12:43 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

9.8

CVSS3.1

CVE-2026-5734 - Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thund…

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affec…

📅 Published: April 7, 2026, 12:43 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

9.8

CVSS3.1

CVE-2026-5731 - Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Fir…

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. Th…

📅 Published: April 7, 2026, 12:43 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.
Total resulsts: 342863
Page 19 of 34,287
« previous page » next page
Filters