2.1

CVSS4.0

CVE-2026-1005 - Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path

Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large va…

πŸ“… Published: March 19, 2026, 5 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

2.2

CVSS4.0

CVE-2026-0819 - Stack buffer overflow in PKCS7 SignedData encoding with custom signed attributes

A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorrect capacity value (esd->signedAttribsCount) to EncodeAttributes() instead of the remaining availabl…

πŸ“… Published: March 19, 2026, 4:54 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

0.0

CVE-2026-3029 - CVE-2026-3029

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

πŸ“… Published: March 19, 2026, 3:53 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32869 - OPEXUS eComplaint and eCASE XSS via Name of Organization field

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case information. An authenticated attacker can inject an XSS payload which is executed in the context of a victim's session when they visit the case information p…

πŸ“… Published: March 19, 2026, 3:49 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32868 - OPEXUS eComplaint and eCASE XSS via my information

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS payload in the first and last name fields. The payload is executed when the full name is rendered. Th…

πŸ“… Published: March 19, 2026, 3:48 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.3

CVSS4.0

CVE-2026-32867 - OPEXUS eComplaint unauthenticated file upload

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadPub.aspx'. Users would see these unexpected files in cases. Uploading a large number of files could consume storage.

πŸ“… Published: March 19, 2026, 3:48 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32866 - OPEXUS eComplaint and eCase stored XSS via profile first and last name

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated attacker can inject parts of an XSS payload in their first and last name fields. The payload is executed when the user's full name is rendered. The at…

πŸ“… Published: March 19, 2026, 3:48 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

9.2

CVSS4.0

CVE-2026-32865 - OPEXUS eComplaint and eCase insecure password reset

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security questions. Existing securit…

πŸ“… Published: March 19, 2026, 3:47 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

7.2

CVSS3.1

CVE-2026-27043 - WordPress Photography theme <= 7.7.5 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a through 7.7.5.

πŸ“… Published: March 19, 2026, 2:49 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32843 - Linkit ONE Location Aware Sensor System (LASS) Reflected XSS via PM25.php

Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting vulnerability in the PM25.php file that allows remote attackers to execute arbitrary JavaScript by injecting malicious code into GET parameters. Attackers can craft a malicious U…

πŸ“… Published: March 19, 2026, 2:39 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.
Total resulsts: 338998
Page 33 of 33,900
Β« previous page Β» next page
Filters