6.5

CVSS3.1

CVE-2026-26940 - Improper Validation of Specified Quantity in Input in Kibana Leading to Denial of Service

Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead Denial of Service via Excessive Allocation (CAPEC-130). The vulnerability allows an authenticated user to send a specially crafted Timelion expression that overwrites internal serie…

πŸ“… Published: March 19, 2026, 5:14 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

6.5

CVSS3.1

CVE-2026-26939 - Missing Authorization in Kibana Leading to Unauthorized Endpoint Response Action Configuration

Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Response Action Configuration (host isolation, process termination, and process suspension) via CAPEC-1 (Accessing Functionality Not Properly Constrained by ACLs). This requires an au…

πŸ“… Published: March 19, 2026, 5:11 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.5

CVSS4.0

CVE-2026-2645 - Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2

In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange message had been received. This issue affects wolfSSL before 5.8.4 (wolfSSL 5.8.2 and earlier is vuln…

πŸ“… Published: March 19, 2026, 5:10 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.7

CVSS3.1

CVE-2026-26933 - Improper Validation of Array Index in Packetbeat Leading to Denial of Service

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface can trigger out-of…

πŸ“… Published: March 19, 2026, 5:08 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.7

CVSS3.1

CVE-2026-26931 - Memory Allocation with Excessive Size Value in Metricbeat Leading to Denial of Service

Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).

πŸ“… Published: March 19, 2026, 5:05 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

2.1

CVSS4.0

CVE-2026-1005 - Integer underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt path

Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large va…

πŸ“… Published: March 19, 2026, 5 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

2.2

CVSS4.0

CVE-2026-0819 - Stack buffer overflow in PKCS7 SignedData encoding with custom signed attributes

A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding custom signed attributes, the code passes an incorrect capacity value (esd->signedAttribsCount) to EncodeAttributes() instead of the remaining availabl…

πŸ“… Published: March 19, 2026, 4:54 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

0.0

CVE-2026-3029 - CVE-2026-3029

A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.

πŸ“… Published: March 19, 2026, 3:53 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32869 - OPEXUS eComplaint and eCASE XSS via Name of Organization field

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field when filling out case information. An authenticated attacker can inject an XSS payload which is executed in the context of a victim's session when they visit the case information p…

πŸ“… Published: March 19, 2026, 3:49 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.

5.1

CVSS4.0

CVE-2026-32868 - OPEXUS eComplaint and eCASE XSS via my information

OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the 'My Information' screen. An authenticated attacker can inject parts of an XSS payload in the first and last name fields. The payload is executed when the full name is rendered. Th…

πŸ“… Published: March 19, 2026, 3:48 p.m. πŸ”„ Last Modified: March 20, 2026, 8:56 a.m.
Total resulsts: 339064
Page 39 of 33,907
Β« previous page Β» next page
Filters