6.9

CVSS4.0

CVE-2018-25228 - NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service

NetSetMan 4.7.1 contains a buffer overflow vulnerability in the Workgroup feature that allows local attackers to crash the application by supplying oversized input. Attackers can create a malicious configuration file with excessive data and paste it into the Workgroup field to trigger a denial of s…

📅 Published: March 30, 2026, 11:02 a.m. 🔄 Last Modified: March 30, 2026, 11:02 a.m.

6.9

CVSS4.0

CVE-2018-25227 - Valentina Studio 9.0.4 Denial of Service via Host Parameter

Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server…

📅 Published: March 30, 2026, 11:02 a.m. 🔄 Last Modified: March 30, 2026, 11:02 a.m.

6.9

CVSS4.0

CVE-2018-25226 - FTPShell Server 6.83 Denial of Service via Account Name

FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter with…

📅 Published: March 30, 2026, 11:02 a.m. 🔄 Last Modified: March 30, 2026, 11:02 a.m.

6.9

CVSS4.0

CVE-2026-1612 - Hard-coded AWS Key in AL-KO Robolinho Update Software

AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket. Using the keys directly might give the attacker greater access than the app itself. Key grants AT LEAST read access to some of the objects in bucket. The vendor was notified ea…

📅 Published: March 30, 2026, 9:56 a.m. 🔄 Last Modified: March 30, 2026, 9:56 a.m.

10

CVSS4.0

CVE-2026-5128 -

A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /users API endpoint to retrieve highly sensitive Steam account data, including the account username, password, identity secret, and shared secret. In add…

📅 Published: March 30, 2026, 9:18 a.m. 🔄 Last Modified: March 30, 2026, 9:42 a.m.

8.5

CVSS4.0

CVE-2026-4416 - GIGABYTE|Performance Library - Insecure Deserialization

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.

📅 Published: March 30, 2026, 7:52 a.m. 🔄 Last Modified: March 30, 2026, 7:52 a.m.

0.0

CVE-2026-5121 - Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arb…

📅 Published: March 30, 2026, 7:47 a.m. 🔄 Last Modified: March 30, 2026, 7:56 a.m.

5.8

CVSS4.0

CVE-2026-25704 - Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData

A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greeter can allow an attacker to regain privileges that should have been dropped and abuse them in the racy checking logic. This issue affects cosmic-greeter before https://github.C…

📅 Published: March 30, 2026, 7:44 a.m. 🔄 Last Modified: March 30, 2026, 7:44 a.m.

9.2

CVSS4.0

CVE-2026-4415 - GIGABYTE|Gigabyte Control Center - Arbitrary File Write

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

📅 Published: March 30, 2026, 7:36 a.m. 🔄 Last Modified: March 30, 2026, 7:53 a.m.

5.3

CVSS4.0

CVE-2025-3716 - User enumeration in ESET Protect (on-prem)

User enumeration in ESET Protect (on-prem) via Response Timing.

📅 Published: March 30, 2026, 7:30 a.m. 🔄 Last Modified: March 30, 2026, 7:30 a.m.
Total resulsts: 341106
Page 2 of 34,111
« previous page » next page
Filters