5.7

CVSS4.0

CVE-2025-68947 - NSecsoft NSecKrnl process termination privilege escalation

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

πŸ“… Published: Jan. 13, 2026, 9:19 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2026-0543 - Improper Input Validation in Kibana Email Connector Leading to Excessive Allocation

Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially crafted email address parameter. This requires an attacker to have authenticated access with view-level privileges sufficient to execute connector ac…

πŸ“… Published: Jan. 13, 2026, 9:10 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.5

CVSS3.1

CVE-2026-0531 - Allocation of Resources Without Limits or Throttling in Kibana Fleet

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted bulk retrieval request. This requires an attacker to have low-level privileges equivalent to the viewer role, which grants read access to agent policie…

πŸ“… Published: Jan. 13, 2026, 9:05 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.5

CVSS3.1

CVE-2026-0530 - Allocation of Resources Without Limits or Throttling in Kibana Leading to Excessive Allocation

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted request. This causes the application to perform redundant processing operations that continuously consume system resources until service degradation or…

πŸ“… Published: Jan. 13, 2026, 9:03 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.5

CVSS3.1

CVE-2026-0528 - Improper Input Validation in Metricbeat Leading to Denial of Service

Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Inpu…

πŸ“… Published: Jan. 13, 2026, 9:02 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

8.7

CVSS4.0

CVE-2026-22871 - GuardDog Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCE

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract() function that allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Overwrit…

πŸ“… Published: Jan. 13, 2026, 8:46 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

7.1

CVSS4.0

CVE-2026-22870 - GuardDog Zip Bomb Vulnerability in safe_extract() Allows DoS

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate decompressed file sizes when extracting ZIP archives (wheels, eggs), allowing attackers to cause denial of service through zip bombs. A malicious package can consume giga…

πŸ“… Published: Jan. 13, 2026, 8:43 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

5.1

CVSS4.0

CVE-2025-15056 - Quill 2.0.3 - Lack of data validation in HTML export allowing XSS

A lack of data validation vulnerability in the HTML export feature in Quill in allows Cross-Site Scripting (XSS). This issue affects Quill: 2.0.3.

πŸ“… Published: Jan. 13, 2026, 8:39 p.m. πŸ”„ Last Modified: April 20, 2026, 2:10 p.m.

8.9

CVSS4.0

CVE-2026-22869 - Eigent Allows Arbitrary Code Execution via pull_request_target CI Workflow

Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution from fork pull requests with repository write permissions. The vulnerable workflow uses pull_request_target trigger combined with checkout of untrusted …

πŸ“… Published: Jan. 13, 2026, 8:38 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

7.1

CVSS4.0

CVE-2026-22868 - go-ethereum has a DoS via malicious p2p message

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.

πŸ“… Published: Jan. 13, 2026, 8:27 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.
Total resulsts: 349182
Page 2151 of 34,919
Β« previous page Β» next page
Filters