9.3

CVSS4.0

CVE-2026-30789 - RustDesk Client Generates Auth Proof Without Client-Side Nonce, Enabling Replay Attacks

Authentication Bypass by Capture-replay, Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authentication modules) allows Reusing Session IDs (aka Session Replay). T…

πŸ“… Published: March 5, 2026, 3:41 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

8.2

CVSS4.0

CVE-2026-30798 - RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload

Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is …

πŸ“… Published: March 5, 2026, 3:38 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

9.3

CVSS4.0

CVE-2026-30797 - RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server

Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files fl…

πŸ“… Published: March 5, 2026, 3:35 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

8.7

CVSS4.0

CVE-2026-25048 - xgrammar: Multi-layer nesting causes DoS

xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.

πŸ“… Published: March 5, 2026, 3:34 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

5.4

CVSS3.1

CVE-2025-64166 - Mercurius: Incorrect Content-Type parsing can lead to CSRF attack

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue arises from incorrect parsing of the Content-Type header in requests. Specifically, requests with Content-Type values such as application/x-www-form-urlen…

πŸ“… Published: March 5, 2026, 3:31 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

8.7

CVSS4.0

CVE-2026-30796 - RustDesk Server Pro API Requires Address Book Password in Plaintext for Sync Protocol

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-server-pro on Windows, MacOS, Linux (Address book sync API modules) allows Sniffing Attacks. This vulnerability is associated with program files Closed source β€” API endpoint handling he…

πŸ“… Published: March 5, 2026, 3:30 p.m. πŸ”„ Last Modified: March 6, 2026, 3:01 p.m.

8.7

CVSS4.0

CVE-2026-30795 - RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure

Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routin…

πŸ“… Published: March 5, 2026, 3:27 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

9.1

CVSS4.0

CVE-2026-30794 - RustDesk HTTP Client Silently Accepts Invalid TLS Certificates After Handshake Failure

Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs an…

πŸ“… Published: March 5, 2026, 3:24 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

9.3

CVSS4.0

CVE-2026-30793 - RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This vulnerability is associated with program files flutter/lib/common.Dart, src/fl…

πŸ“… Published: March 5, 2026, 3:21 p.m. πŸ”„ Last Modified: March 5, 2026, 7:38 p.m.

9.1

CVSS4.0

CVE-2026-30792 - RustDesk Client Blindly Merges Unauthenticated Strategy Payloads, Bypassing Local Security Settings

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-the-Middle. This vulnerability is associated with program files…

πŸ“… Published: March 5, 2026, 3:14 p.m. πŸ”„ Last Modified: March 6, 2026, 10:25 a.m.
Total resulsts: 336512
Page 38 of 33,652
Β« previous page Β» next page
Filters