8.7

CVSS3.1

CVE-2026-34728 - phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is triggered, the user-supplied name parameter is concatenated with the base upload directory path without any p…

πŸ“… Published: April 2, 2026, 2:44 p.m. πŸ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.4

CVSS4.0

CVE-2026-32629 - phpMyFAQ: Stored XSS via Unsanitized Email Field in Admin FAQ Editor

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that is syntactically valid per RFC 5321 (quoted local part) yet contains raw HTML β€” for example "<script>alert(1)</script>"@evil.com. PHP's FILTER_VALIDA…

πŸ“… Published: April 2, 2026, 2:43 p.m. πŸ”„ Last Modified: April 2, 2026, 8:20 p.m.

7.5

CVSS3.1

CVE-2026-31937 - Suricata dcerpc: quadratic complexity in dcerpc buffering

Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.

πŸ“… Published: April 2, 2026, 2:38 p.m. πŸ”„ Last Modified: April 3, 2026, 9:18 a.m.

7.5

CVSS3.1

CVE-2026-31935 - Suricata http2: unbounded resource consumption

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.

πŸ“… Published: April 2, 2026, 2:36 p.m. πŸ”„ Last Modified: April 2, 2026, 8:20 p.m.

9.3

CVSS4.0

CVE-2026-35002 - Agno < 2.3.24 field_type Eval Injection Arbitrary Code Execution

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achiev…

πŸ“… Published: April 2, 2026, 2:34 p.m. πŸ”„ Last Modified: April 2, 2026, 8:20 p.m.

6.9

CVSS4.0

CVE-2026-5342 - LibRaw TIFF/NEF decoders_libraw.cpp nikon_load_padded_packed_raw out-of-bounds

A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file src/decoders/decoders_libraw.cpp of the component TIFF/NEF. Executing a manipulation of the argument load_flags/raw_width can lead to out-of-bounds read. It is possible to launch…

πŸ“… Published: April 2, 2026, 2:30 p.m. πŸ”„ Last Modified: April 2, 2026, 8:20 p.m.

7.5

CVSS3.1

CVE-2026-31934 - Suricata smtp/mine: quadratic complexity in extracting urls

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.

πŸ“… Published: April 2, 2026, 2:21 p.m. πŸ”„ Last Modified: April 3, 2026, 9:18 a.m.

5.1

CVSS4.0

CVE-2026-5339 - Tenda G103 Setting gpon.lua action_set_net_settings command injection

A vulnerability was detected in Tenda G103 1.0.0.5. The impacted element is the function action_set_net_settings of the file gpon.lua of the component Setting Handler. Performing a manipulation of the argument authLoid/authLoidPassword/authPassword/authSerialNo/authType/oltType/usVlanId/usVlanPrior…

πŸ“… Published: April 2, 2026, 2:15 p.m. πŸ”„ Last Modified: April 2, 2026, 8:21 p.m.

7.5

CVSS3.1

CVE-2026-31933 - Suricata stream: quadratic complexity in stream inspection

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.

πŸ“… Published: April 2, 2026, 2:03 p.m. πŸ”„ Last Modified: April 3, 2026, 9:18 a.m.

7.5

CVSS3.1

CVE-2026-31932 - Suricata krb5: quadratic complexity in krb5 buffering

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.

πŸ“… Published: April 2, 2026, 2:02 p.m. πŸ”„ Last Modified: April 3, 2026, 9:18 a.m.
Total resulsts: 342025
Page 23 of 34,203
Β« previous page Β» next page
Filters