5.7

CVSS4.0

CVE-2026-33542 - Incus does not verify combined fingerprint when downloading images from simplestreams servers

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker con…

πŸ“… Published: March 26, 2026, 10:32 p.m. πŸ”„ Last Modified: March 27, 2026, 3:47 p.m.

8.5

CVSS3.1

CVE-2026-34352 - TigerVNC: x0vncserver: TigerVNC x0vncserver: Information disclosure, data manipulation, and denial …

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

πŸ“… Published: March 26, 2026, 10:30 p.m. πŸ”„ Last Modified: March 27, 2026, 3:47 p.m.

8.7

CVSS4.0

CVE-2026-4903 - Tenda AC5 POST Request QuickIndex formQuickIndex memory corruption

A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. This manipulation of the argument PPPOEPassword causes stack-based buffer overflow. The attack may be initiated remotely. The …

πŸ“… Published: March 26, 2026, 10:30 p.m. πŸ”„ Last Modified: March 27, 2026, 8:31 a.m.

8.7

CVSS4.0

CVE-2026-4902 - Tenda AC5 POST Request addressNat fromAddressNat memory corruption

A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now…

πŸ“… Published: March 26, 2026, 10:30 p.m. πŸ”„ Last Modified: March 27, 2026, 8:31 a.m.

6.9

CVSS4.0

CVE-2026-4900 - code-projects Online Food Ordering System localhost.sql privilege escalation

A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to the public and coul…

πŸ“… Published: March 26, 2026, 9:56 p.m. πŸ”„ Last Modified: March 27, 2026, 8:31 a.m.

4.8

CVSS4.0

CVE-2026-4899 - code-projects Online Food Ordering System food.php cross site scripting

A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argument cuisines results in cross site scripting. It is possible to launch the attack remotely. The explo…

πŸ“… Published: March 26, 2026, 9:56 p.m. πŸ”„ Last Modified: March 27, 2026, 8:31 a.m.

8.8

CVSS3.1

CVE-2026-33686 - Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtil

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, allowing path separators to be passed into the storage layer. In `src/Utils/FileUt…

πŸ“… Published: March 26, 2026, 9:54 p.m. πŸ”„ Last Modified: March 27, 2026, 1:59 p.m.

8.8

CVSS3.1

CVE-2026-33687 - Sharp has Unrestricted File Upload via Client-Controlled Validation Rules

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-contro…

πŸ“… Published: March 26, 2026, 9:47 p.m. πŸ”„ Last Modified: March 27, 2026, 8:28 p.m.

4.7

CVSS3.1

CVE-2026-33682 - Streamlit on Windows has Unauthenticated SSRF Vulnerability (NTLM Credential Exposure)

Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesys…

πŸ“… Published: March 26, 2026, 9:45 p.m. πŸ”„ Last Modified: March 27, 2026, 8 p.m.

2

CVSS3.1

CVE-2026-33674 - PrestaShop: Improper Use of Validation Framework

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.

πŸ“… Published: March 26, 2026, 9:42 p.m. πŸ”„ Last Modified: March 26, 2026, 10:16 p.m.
Total resulsts: 341037
Page 33 of 34,104
Β« previous page Β» next page
Filters