10.0

CVSS3.1

CVE-2025-15379 - Command Injection in mlflow/mlflow

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` โ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:16 a.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:41 p.m.

8.7

CVSS4.0

CVE-2026-3945 - Integer Overflow in Tinyproxy Chunked Transfer Parsing Causes DoS

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol() without properly validatiโ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:05 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

7.5

CVSS3.1

CVE-2026-2328 - Backend Access Due to Insufficient Input Validation

An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.

๐Ÿ“… Published: March 30, 2026, 6:55 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

5.9

CVSS3.1

CVE-2026-5119 - Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel โ€ฆ

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential sesโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

2.3

CVSS4.0

CVE-2026-5107 - FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to hโ€ฆ

๐Ÿ“… Published: March 30, 2026, 5 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 4:02 p.m.

4.8

CVSS4.0

CVE-2026-5106 - code-projects Exam Form Submission update_fst.php cross site scripting

A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_fst.php. Executing a manipulation of the argument sname can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publishโ€ฆ

๐Ÿ“… Published: March 30, 2026, 4 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

5.3

CVSS4.0

CVE-2026-5105 - Totolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection

A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. Performing a manipulation of the argument pptpPassThru results in command injection. It is possible to initโ€ฆ

๐Ÿ“… Published: March 30, 2026, 3 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

5.3

CVSS4.0

CVE-2026-5104 - Totolink A3300R cstecgi.cgi setStaticRoute command injection

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ip leads to command injection. The attack may be performed from remote. The exploit has been disclosed puโ€ฆ

๐Ÿ“… Published: March 30, 2026, 2 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:56 p.m.

7.5

CVSS3.1

CVE-2026-3124 - Download Monitor <= 5.1.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Comโ€ฆ

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary peโ€ฆ

๐Ÿ“… Published: March 30, 2026, 1:24 a.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

9.6

CVSS3.1

CVE-2025-15036 - Path Traversal Vulnerability in mlflow/mlflow

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extractiโ€ฆ

๐Ÿ“… Published: March 30, 2026, 1:16 a.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8 p.m.
Total resulsts: 341475
Page 37 of 34,148
ยซ previous page ยป next page
Filters