6.9

CVSS4.0

CVE-2026-33027 - Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operationโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:59 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 7:16 p.m.

7.1

CVSS4.0

CVE-2026-33028 - Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primaโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:59 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

6.9

CVSS4.0

CVE-2026-33029 - Nginx UI: DoS via Negative Integer Input in Logrotate Interval

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enterโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:59 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

8.8

CVSS3.1

CVE-2026-33030 - Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base Model structโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

9.8

CVSS3.1

CVE-2026-33032 - Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message โ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:58 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-4046 - iconv crash due to assertion failure with untrusted input

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 aโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:16 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.8

CVSS3.1

CVE-2025-66215 - OpenSC: Stack-buffer-overflow WRITE in card-oberthur

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, an attacker with physical access to the computer at the time user or administrator uses a token can cause a stack-buffer-overflow WRITE in card-oberthur. The attack requires crafted USB device or smart card that woulโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:06 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.9

CVSS3.1

CVE-2025-66038 - OpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, sc_compacttlv_find_tag searches a compact-TLV buffer for a given tag. In compact-TLV, a single byte encodes the tag (high nibble) and value length (low nibble). With a 1-byte buffer {0x0A}, the encoded element claimsโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:03 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

3.9

CVSS3.1

CVE-2025-66037 - OpenSC: Out of Bounds vulnerability

OpenSC is an open source smart card tools and middleware. Prior to version 0.27.0, feeding a crafted input to the fuzz_pkcs15_reader harness causes OpenSC to perform an out-of-bounds heap read in the X.509/SPKI handling path. Specifically, sc_pkcs15_pubkey_from_spki_fields() allocates a zero-lengthโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:01 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.

4.8

CVSS4.0

CVE-2026-5125 - raine consult-llm-mcp server.ts child_process.execSync os command injection

A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument git_diff.base_ref/git_diff.files results in os command injection. The attack is only possible with locโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:55 p.m.
Total resulsts: 341475
Page 32 of 34,148
ยซ previous page ยป next page
Filters