9.2

CVSS4.0

CVE-2026-28205 - Initialization of a resource with an insecure default in OpenPLC_V3

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API.

πŸ“… Published: April 9, 2026, 6:54 p.m. πŸ”„ Last Modified: April 10, 2026, 6:02 p.m.

6.1

CVSS4.0

CVE-2026-35186 - Wasmtime has an improperly masked return value from `table.grow` with Winch compiler backend

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result to be incorrectly typed. For 32-bit tables this means that the result of the operator, internally in …

πŸ“… Published: April 9, 2026, 6:54 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

2.3

CVSS4.0

CVE-2026-34988 - Wasmtime leaks data between pooling allocator instances

Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of its pooling allocator contains a bug where in certain configurations the contents of linear memory can be leaked from one instance to the next. The implementation of resetting the v…

πŸ“… Published: April 9, 2026, 6:52 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

9

CVSS4.0

CVE-2026-34987 - Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox. This vulnerability requires use of the Winch…

πŸ“… Published: April 9, 2026, 6:48 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

1

CVSS4.0

CVE-2026-34983 - Wasmtime has a use-after-free bug after cloning `wasmtime::Linker`

Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free bugs. This bug is not controllable by guest Wasm programs. It can only be triggered by a specific sequence of embedder API calls made by the host. Specifically, the following ste…

πŸ“… Published: April 9, 2026, 6:47 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

9

CVSS4.0

CVE-2026-34971 - Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift

Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks a gu…

πŸ“… Published: April 9, 2026, 6:45 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

5.9

CVSS4.0

CVE-2026-34946 - Wasmtime's host panics when Winch compiler executes `table.fill`

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill instruction can result in a host panic. This means that a valid guest can be compiled with Winch, on any architecture, …

πŸ“… Published: April 9, 2026, 6:43 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

2.3

CVSS4.0

CVE-2026-34945 - Wasmtime leaks host data with 64-bit tables and Winch

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the table.size instruction. This bug could lead to disclosing data on the host…

πŸ“… Published: April 9, 2026, 6:40 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

4.1

CVSS4.0

CVE-2026-34944 - Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the f64x2.splat WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When signals-based-traps are disabled this can result …

πŸ“… Published: April 9, 2026, 6:38 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.

5.6

CVSS4.0

CVE-2026-34943 - Wasmtime panics when lifting `flags` component value

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic which can happen when a flags-typed component model value is lifted with the Val type. If bits are set outside of the set of flags the component model specifies that these bits sho…

πŸ“… Published: April 9, 2026, 6:36 p.m. πŸ”„ Last Modified: April 9, 2026, 7:16 p.m.
Total resulsts: 343928
Page 40 of 34,393
Β« previous page Β» next page
Filters