8.6

CVSS4.0

CVE-2026-3342 - WatchGuard Firebox Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and inโ€ฆ

๐Ÿ“… Published: March 3, 2026, 1:17 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 1:17 p.m.

2.1

CVSS4.0

CVE-2026-3351 - Authorization Bypass in LXD GET /1.0/certificates Endpoint

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

๐Ÿ“… Published: March 3, 2026, 12:49 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 12:49 p.m.

4.8

CVSS4.0

CVE-2026-3463 - xlnt-community xlnt Compound Document binary.hpp append heap-based overflow

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locallโ€ฆ

๐Ÿ“… Published: March 3, 2026, 12:02 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 12:02 p.m.

0.0

CVE-2025-59060 - Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

๐Ÿ“… Published: March 3, 2026, 10:46 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:46 a.m.

0.0

CVE-2025-59059 - Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

๐Ÿ“… Published: March 3, 2026, 10:44 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 10:44 a.m.

6.3

CVSS4.0

CVE-2025-15598 - Dataease SQLBot JWT Token auth.py validateEmbedded signature verification

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiaโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:32 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 9:32 a.m.

7.2

CVSS3.1

CVE-2026-2568 - WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthentiโ€ฆ

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possibleโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:24 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 9:24 a.m.

9.8

CVSS3.1

CVE-2026-22886 -

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues tโ€ฆ

๐Ÿ“… Published: March 3, 2026, 9:18 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 9:20 a.m.

8.7

CVSS4.0

CVE-2026-1876 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet module

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. Aโ€ฆ

๐Ÿ“… Published: March 3, 2026, 7:03 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 7:03 a.m.

8.7

CVSS4.0

CVE-2026-1875 - Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP all versions allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A systโ€ฆ

๐Ÿ“… Published: March 3, 2026, 6:54 a.m. ๐Ÿ”„ Last Modified: March 3, 2026, 6:54 a.m.
Total resulsts: 335477
Page 2 of 33,548
ยซ previous page ยป next page
Filters