8.6

CVSS4.0

CVE-2016-20038 - yTree 1.94-1.1 Stack-Based Buffer Overflow

yTree 1.94-1.1 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an excessively long argument to the application. Attackers can craft a malicious command-line argument containing shellcode and a return address to overwrite the st…

πŸ“… Published: March 28, 2026, 11:58 a.m. πŸ”„ Last Modified: March 28, 2026, 11:58 a.m.

8.6

CVSS4.0

CVE-2016-20037 - xwpe 1.5.30a-2.1 Stack-based Buffer Overflow

xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying overly long input strings that exceed buffer boundaries. Attackers can craft malicious command-line arguments with 262 bytes of junk data followed by sh…

πŸ“… Published: March 28, 2026, 11:57 a.m. πŸ”„ Last Modified: March 28, 2026, 11:57 a.m.

6.9

CVSS4.0

CVE-2026-4996 - Sinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql injection

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_l…

πŸ“… Published: March 28, 2026, 11:30 a.m. πŸ”„ Last Modified: March 28, 2026, 11:30 a.m.

5.4

CVSS3.1

CVE-2026-2595 - Quads Ads Manager for Google AdSense <= 2.0.98.1 - Authenticated (Contributor+) Stored Cross-Site S…

The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.98.1 due to insufficient input sanitization and output escaping of multiple ad metadata parameters. This makes it possible for authenticated attackers, wi…

πŸ“… Published: March 28, 2026, 11:26 a.m. πŸ”„ Last Modified: March 28, 2026, 11:26 a.m.

5.5

CVSS4.0

CVE-2025-9497 - Hardcoded Upgrade Decryption Passwords

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

πŸ“… Published: March 28, 2026, 10:58 a.m. πŸ”„ Last Modified: March 28, 2026, 10:58 a.m.

5.1

CVSS4.0

CVE-2026-4995 - wandb OpenUI Window Message Event index.html cross site scripting

A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message Event Handler. This manipulation causes cross site scripting. The attack can be initiated remotely. T…

πŸ“… Published: March 28, 2026, 10:45 a.m. πŸ”„ Last Modified: March 28, 2026, 10:45 a.m.

5.3

CVSS3.1

CVE-2026-2442 - Pagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Inje…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.0.7. This is due to the contact form handler performing placeholder substitution on attacker-control…

πŸ“… Published: March 28, 2026, 9:27 a.m. πŸ”„ Last Modified: March 28, 2026, 9:27 a.m.

5.1

CVSS4.0

CVE-2026-4994 - wandb OpenUI APIStatusError server.py generic_exception_handler information exposure

A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The manipulation of the argument key results in information exposure through error message. Access to the lo…

πŸ“… Published: March 28, 2026, 9:15 a.m. πŸ”„ Last Modified: March 28, 2026, 9:15 a.m.

4.8

CVSS4.0

CVE-2026-4993 - wandb OpenUI config.py hard-coded credentials

A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the…

πŸ“… Published: March 28, 2026, 9:15 a.m. πŸ”„ Last Modified: March 28, 2026, 9:15 a.m.

0.0

CVE-2026-23399 - nf_tables: nft_dynset: fix possible stateful expression memleak in error path

In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expression memleak in error path If cloning the second stateful expression in the element via GFP_ATOMIC fails, then the first stateful expression remains in place without being releas…

πŸ“… Published: March 28, 2026, 7:16 a.m. πŸ”„ Last Modified: March 28, 2026, 7:16 a.m.
Total resulsts: 341013
Page 4 of 34,102
Β« previous page Β» next page
Filters