8.5

CVSS4.0

CVE-2026-2637 -

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd.Β The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks. This issue affects iBoysoft NTFS: 8.0.0.

πŸ“… Published: March 3, 2026, 2:04 p.m. πŸ”„ Last Modified: March 3, 2026, 2:04 p.m.

6.9

CVSS4.0

CVE-2026-3344 - WatchGuard Firebox System Integrity Check Bypass

A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: March 4, 2026, 7:19 p.m.

5.1

CVSS4.0

CVE-2026-3343 - WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. This vulnerability affects Fireware OS 12.7 up to and including 12.11.7…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: March 4, 2026, 7:34 p.m.

8.6

CVSS4.0

CVE-2026-3342 - WatchGuard Firebox Out of Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and in…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: March 4, 2026, 7:42 p.m.

2.1

CVSS4.0

CVE-2026-3351 - Authorization Bypass in LXD GET /1.0/certificates Endpoint

Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.

πŸ“… Published: March 3, 2026, 12:49 p.m. πŸ”„ Last Modified: March 3, 2026, 12:49 p.m.

4.8

CVSS4.0

CVE-2026-3463 - xlnt-community xlnt Compound Document binary.hpp append heap-based overflow

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locall…

πŸ“… Published: March 3, 2026, 12:02 p.m. πŸ”„ Last Modified: March 3, 2026, 12:02 p.m.

5.3

CVSS3.1

CVE-2025-59060 - Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

πŸ“… Published: March 3, 2026, 10:46 a.m. πŸ”„ Last Modified: March 4, 2026, 2:54 p.m.

9.8

CVSS3.1

CVE-2025-59059 - Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

πŸ“… Published: March 3, 2026, 10:44 a.m. πŸ”„ Last Modified: March 4, 2026, 2:54 p.m.

6.3

CVSS4.0

CVE-2025-15598 - Dataease SQLBot JWT Token auth.py validateEmbedded signature verification

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initia…

πŸ“… Published: March 3, 2026, 9:32 a.m. πŸ”„ Last Modified: March 4, 2026, 2:54 p.m.

7.2

CVSS3.1

CVE-2026-2568 - WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.5 - Unauthenti…

The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission data in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible…

πŸ“… Published: March 3, 2026, 9:24 a.m. πŸ”„ Last Modified: March 3, 2026, 9:24 a.m.
Total resulsts: 335750
Page 25 of 33,575
Β« previous page Β» next page
Filters