4

CVSS3.1

CVE-2026-40396 -

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed (timeout_…

πŸ“… Published: April 12, 2026, 7:23 p.m. πŸ”„ Last Modified: April 12, 2026, 7:24 p.m.

4

CVSS3.1

CVE-2026-40395 -

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writable…

πŸ“… Published: April 12, 2026, 7:21 p.m. πŸ”„ Last Modified: April 12, 2026, 7:24 p.m.

4

CVSS3.1

CVE-2026-40394 -

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repur…

πŸ“… Published: April 12, 2026, 7:17 p.m. πŸ”„ Last Modified: April 12, 2026, 7:23 p.m.

8.1

CVSS3.1

CVE-2026-40393 -

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

πŸ“… Published: April 12, 2026, 6:49 p.m. πŸ”„ Last Modified: April 12, 2026, 6:56 p.m.

4

CVSS3.1

CVE-2026-40386 -

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

πŸ“… Published: April 12, 2026, 6:19 p.m. πŸ”„ Last Modified: April 12, 2026, 6:22 p.m.

4

CVSS3.1

CVE-2026-40385 -

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

πŸ“… Published: April 12, 2026, 6:16 p.m. πŸ”„ Last Modified: April 12, 2026, 6:22 p.m.

7.1

CVSS4.0

CVE-2019-25713 - MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter

MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blin…

πŸ“… Published: April 12, 2026, 12:28 p.m. πŸ”„ Last Modified: April 12, 2026, 12:28 p.m.

6.9

CVSS4.0

CVE-2019-25712 - BlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration Key

BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registratio…

πŸ“… Published: April 12, 2026, 12:28 p.m. πŸ”„ Last Modified: April 12, 2026, 12:28 p.m.

6.9

CVSS4.0

CVE-2019-25711 - SpotFTP Password Recover 2.4.2 Denial of Service via Name Field

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash w…

πŸ“… Published: April 12, 2026, 12:28 p.m. πŸ”„ Last Modified: April 12, 2026, 12:28 p.m.

8.8

CVSS4.0

CVE-2019-25710 - Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error…

πŸ“… Published: April 12, 2026, 12:28 p.m. πŸ”„ Last Modified: April 12, 2026, 12:28 p.m.
Total resulsts: 343984
Page 2 of 34,399
Β« previous page Β» next page
Filters