9.8

CVSS3.1

CVE-2026-33032 - Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message โ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-4046 - iconv crash due to assertion failure with untrusted input

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 aโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:16 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.8

CVSS3.1

CVE-2025-66215 - OpenSC: Stack-buffer-overflow WRITE in card-oberthur

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that woulโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:06 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.9

CVSS3.1

CVE-2025-66038 - OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). With a 1-byte buffer {0x0A}, the encoded element claimsโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:03 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.9

CVSS3.1

CVE-2025-66037 - OpenSC: Out of Bounds vulnerability

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc_pkcs15_pubkey_from_spki_fields() allocates a zero-lengthโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:01 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

4.8

CVSS4.0

CVE-2026-5125 - raine consult-llm-mcp server.ts child_process.execSync os command injection

A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument git_diff.base_ref/git_diff.files results in os command injection. The attack is only possible with locโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.8

CVSS3.1

CVE-2025-49010 - OpenSC: Stack-buffer-overflow WRITE in GET RESPONSE

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow write in GET RESPONSE. The attack requires crafted USB device or smart card that wouldโ€ฆ

๐Ÿ“… Published: March 30, 2026, 4:59 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8 p.m.

5.1

CVSS4.0

CVE-2026-27508 - Smoothwall Express < 3.1 Update 13 Reflected XSS in redirect.cgi via url Parameter

Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsersโ€ฆ

๐Ÿ“… Published: March 30, 2026, 4:51 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

5.1

CVSS4.0

CVE-2026-26352 - Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter

Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes whenโ€ฆ

๐Ÿ“… Published: March 30, 2026, 4:49 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

6.3

CVSS4.0

CVE-2026-5124 - osrg GoBGP BGP Header bgp.go BGPHeader.DecodeFromBytes access control

A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component BGP Header Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The attaโ€ฆ

๐Ÿ“… Published: March 30, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.
Total resulsts: 341471
Page 32 of 34,148
ยซ previous page ยป next page
Filters