4.8

CVSS4.0

CVE-2026-4010 - ThakeeNathees pocketlang pkByteBufferAddString memory corruption

A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected element is the function pkByteBufferAddString. The manipulation of the argument length with the input 4294967290 results in memory corruption. The attack requires a local approach. The…

πŸ“… Published: March 12, 2026, 7:32 a.m. πŸ”„ Last Modified: March 12, 2026, 7:32 a.m.

4.8

CVSS4.0

CVE-2026-4009 - jarikomppa soloud WAV File dr_wav.h drwav_read_pcm_frames_s16__msadpcm out-of-bounds

A vulnerability has been found in jarikomppa soloud up to 20200207. Impacted is the function drwav_read_pcm_frames_s16__msadpcm in the library src/audiosource/wav/dr_wav.h of the component WAV File Parser. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The e…

πŸ“… Published: March 12, 2026, 7:02 a.m. πŸ”„ Last Modified: March 12, 2026, 7:02 a.m.

8.7

CVSS4.0

CVE-2026-4008 - Tenda W3 POST Parameter wifiSSIDset stack-based overflow

A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSIDset of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to launch the attack remotel…

πŸ“… Published: March 12, 2026, 6:32 a.m. πŸ”„ Last Modified: March 12, 2026, 6:32 a.m.

8.7

CVSS4.0

CVE-2026-4007 - Tenda W3 POST Parameter wifiSSIDget stack-based overflow

A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to initiate the attack remo…

πŸ“… Published: March 12, 2026, 6:32 a.m. πŸ”„ Last Modified: March 12, 2026, 6:32 a.m.

4.8

CVSS4.0

CVE-2026-3994 - rui314 mold Object File input-files.cc initialize_sections heap-based overflow

A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a re…

πŸ“… Published: March 12, 2026, 6:02 a.m. πŸ”„ Last Modified: March 12, 2026, 6:02 a.m.

5.3

CVSS4.0

CVE-2026-3993 - itsourcecode Payroll Management System manage_employee_deductions.php cross site scripting

A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unknown code of the file /manage_employee_deductions.php. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has bee…

πŸ“… Published: March 12, 2026, 6:02 a.m. πŸ”„ Last Modified: March 12, 2026, 6:02 a.m.

0.0

CVE-2026-2687 - Reading progressbar < 1.3.1 - Admin+ Stored XSS

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: March 12, 2026, 6 a.m. πŸ”„ Last Modified: March 12, 2026, 6 a.m.

0.0

CVE-2025-15473 - Timetics < 1.0.52 - Unauthenticated Payment/Booking Status Update

The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking" custom post type.

πŸ“… Published: March 12, 2026, 6 a.m. πŸ”„ Last Modified: March 12, 2026, 6 a.m.

5.3

CVSS4.0

CVE-2026-3992 - CodeGenieApp serverless-express Users Endpoint dynamodb.ts injection

A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This manipulation of the argument filter causes injection. The attack may be initiated remotely. The exploit has been made avai…

πŸ“… Published: March 12, 2026, 5:32 a.m. πŸ”„ Last Modified: March 12, 2026, 5:32 a.m.

5.3

CVSS4.0

CVE-2026-3990 - CesiumGS CesiumJS standalone.html cross site scripting

A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. Affected by this issue is some unknown functionality of the file Apps/Sandcastle/standalone.html. The manipulation of the argument c results in cross site scripting. The attack can be launched remotely. The exploit has been rel…

πŸ“… Published: March 12, 2026, 5:32 a.m. πŸ”„ Last Modified: March 12, 2026, 5:32 a.m.
Total resulsts: 337548
Page 2 of 33,755
Β« previous page Β» next page
Filters