5.3

CVSS3.0

CVE-2026-21714 -

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnera…

📅 Published: March 30, 2026, 7:07 p.m. 🔄 Last Modified: March 30, 2026, 7:07 p.m.

6.9

CVSS4.0

CVE-2026-5147 - YunaiV yudao-cloud get-by-website sql injection

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-website. The manipulation of the argument Website results in sql injection. It is possible to launch the attack remotely. The exploit has been released t…

📅 Published: March 30, 2026, 6:45 p.m. 🔄 Last Modified: March 30, 2026, 6:45 p.m.

9.2

CVSS3.1

CVE-2026-34714 -

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

📅 Published: March 30, 2026, 6:27 p.m. 🔄 Last Modified: March 30, 2026, 6:27 p.m.

7.8

CVSS3.1

CVE-2026-3991 - Elevation of Privileges in Symantec Data Loss Prevention Windows Endpoint

Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 MP2 HF15, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elev…

📅 Published: March 30, 2026, 6:27 p.m. 🔄 Last Modified: March 30, 2026, 6:27 p.m.

7.8

CVSS3.1

CVE-2026-3502 - TrueConf Client Update Integrity Verification Bypass

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code executi…

📅 Published: March 30, 2026, 6:05 p.m. 🔄 Last Modified: March 30, 2026, 6:05 p.m.

5.3

CVSS4.0

CVE-2026-5126 - SourceCodester RSS Feed Parser file_get_contents server-side request forgery

A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

📅 Published: March 30, 2026, 6 p.m. 🔄 Last Modified: March 30, 2026, 6:16 p.m.

6.9

CVSS4.0

CVE-2026-33027 - Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation…

📅 Published: March 30, 2026, 5:59 p.m. 🔄 Last Modified: March 30, 2026, 7:16 p.m.

7.1

CVSS4.0

CVE-2026-33028 - Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the prima…

📅 Published: March 30, 2026, 5:59 p.m. 🔄 Last Modified: March 30, 2026, 5:59 p.m.

6.9

CVSS4.0

CVE-2026-33029 - Nginx UI: DoS via Negative Integer Input in Logrotate Interval

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enter…

📅 Published: March 30, 2026, 5:59 p.m. 🔄 Last Modified: March 30, 2026, 5:59 p.m.

8.8

CVSS3.1

CVE-2026-33030 - Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base Model struct…

📅 Published: March 30, 2026, 5:58 p.m. 🔄 Last Modified: March 30, 2026, 5:58 p.m.
Total resulsts: 341178
Page 2 of 34,118
« previous page » next page
Filters