7.7

CVSS3.1

CVE-2026-23881 - Kyverno Denial of Service via Context Variable Amplification in Policy Engine

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially ampl…

πŸ“… Published: Jan. 27, 2026, 4:10 p.m. πŸ”„ Last Modified: April 18, 2026, 2:15 a.m.

10

CVSS3.1

CVE-2026-22039 - Kyverno Cross-Namespace Privilege Escalation via Policy apiCall

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller ServiceAccount, with no …

πŸ“… Published: Jan. 27, 2026, 4:07 p.m. πŸ”„ Last Modified: April 18, 2026, 2:15 a.m.

6.5

CVSS3.1

CVE-2026-24868 - Mitigation bypass in the Privacy: Anti-Tracking component

Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.

πŸ“… Published: Jan. 27, 2026, 3:58 p.m. πŸ”„ Last Modified: April 15, 2026, 6 p.m.

8.8

CVSS3.1

CVE-2026-24869 - Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.

πŸ“… Published: Jan. 27, 2026, 3:58 p.m. πŸ”„ Last Modified: April 15, 2026, 6 p.m.

7.8

CVSS3.1

CVE-2026-24875 - Integer overflow in modizer

Integer Overflow or Wraparound vulnerability in yoyofr modizer.This issue affects modizer: before 4.1.1.

πŸ“… Published: Jan. 27, 2026, 3:55 p.m. πŸ”„ Last Modified: April 18, 2026, 2:15 a.m.

9.1

CVSS3.1

CVE-2026-24874 - Type confusion in xray-monolith

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.

πŸ“… Published: Jan. 27, 2026, 3:55 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 p.m.

7.8

CVSS3.1

CVE-2026-24873 - Out-of-bounds read in lpp-vita

Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita.This issue affects lpp-vita: before lpp-vita r6.

πŸ“… Published: Jan. 27, 2026, 3:53 p.m. πŸ”„ Last Modified: April 18, 2026, 3 p.m.

9.1

CVSS3.1

CVE-2025-68670 - xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote atta…

πŸ“… Published: Jan. 27, 2026, 3:52 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 7:59 p.m.

9.8

CVSS3.1

CVE-2026-24872 - Pointer arithmetic error in SkyFire_548

improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.

πŸ“… Published: Jan. 27, 2026, 3:51 p.m. πŸ”„ Last Modified: April 18, 2026, 7 p.m.

10

CVSS4.0

CVE-2026-24871 - Code injection in Minecraft-Rcon-Manage

Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Manage: before 3.0.

πŸ“… Published: Jan. 27, 2026, 3:50 p.m. πŸ”„ Last Modified: April 18, 2026, 3 p.m.
Total resulsts: 349182
Page 1929 of 34,919
Β« previous page Β» next page
Filters