4.3

CVSS3.1

CVE-2026-33532 - yaml is vulnerable to Stack Overflow via deeply nested YAML collections

`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branch prior to 1.10.3 or on the 2.x branch prior to 2.8.3 may throw a RangeError due to a stack overflow. The node resolution/composition phase uses recursive function calls without a…

πŸ“… Published: March 26, 2026, 7:49 p.m. πŸ”„ Last Modified: March 27, 2026, 3:47 p.m.

0.0

CVE-2026-32287 - Infinite loop in github.com/antchfx/xpath

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered by top-level selectors such as "1=1" or "true()".

πŸ“… Published: March 26, 2026, 7:40 p.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

7.5

CVSS3.1

CVE-2026-32286 - Denial of service in github.com/jackc/pgproto3/v2

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

πŸ“… Published: March 26, 2026, 7:40 p.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

7.5

CVSS3.1

CVE-2026-32285 - Denial of service in github.com/buger/jsonparser

The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.

πŸ“… Published: March 26, 2026, 7:40 p.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

5.9

CVSS3.1

CVE-2026-32284 - Denial of service in github.com/shamaton/msgpack

The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format codes 0xd4-0xd8). This can lead to an out-of-bounds read and a runtime panic, allowing a denial of service attack.

πŸ“… Published: March 26, 2026, 7:40 p.m. πŸ”„ Last Modified: March 29, 2026, 8:27 p.m.

4.9

CVSS4.0

CVE-2026-33531 - InvenTree has Path Traversal In Report Templates

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the report template engine allows a staff-level user to read arbitrary files from the server filesystem via crafted template tags. Affected functions: `encode_svg_image()`, `asset()`, …

πŸ“… Published: March 26, 2026, 7:40 p.m. πŸ”„ Last Modified: March 27, 2026, 7:47 p.m.

7.7

CVSS3.1

CVE-2026-33530 - InvenTree Vulnerable to ORM Filter Injection

InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with bulk data operations can be hijacked to exfiltrate sensitive information from the database. The bulk operation API endpoints (e.g. `/api/part/`, `/api/stock/`, `/api/order/so/alloc…

πŸ“… Published: March 26, 2026, 7:34 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

8.4

CVSS4.0

CVE-2026-33632 - ClearanceKit: opfilter policy bypass via exchangedata and clone operations

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.4, two file operation event types β€” ES_EVENT_TYPE_AUTH_EXCHANGEDATA and ES_EVENT_TYPE_AUTH_CLONE β€” were not intercepted by ClearanceKit's opfilter system extension, allowing loc…

πŸ“… Published: March 26, 2026, 7:32 p.m. πŸ”„ Last Modified: March 27, 2026, 8:32 a.m.

8.7

CVSS3.1

CVE-2026-33631 - ClearanceKit: opfilter policy bypass via non-open file operations

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the 4.1 branch and earlier, the opfilter Endpoint Security system extension enforced file access policy exclusively by intercepting ES_EVENT_TYPE_AUTH_OPEN events. Seven additional fi…

πŸ“… Published: March 26, 2026, 7:30 p.m. πŸ”„ Last Modified: March 27, 2026, 8:33 a.m.

6.9

CVSS4.0

CVE-2021-4474 - Ruckus AP CLI Arbitrary File Read Allows Authenticated Remote File Access

Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows authenticated remote attackers with administrative privileges to read arbitrary files from the underlying filesystem. Attackers can exploit this vulnerability to access sensitive info…

πŸ“… Published: March 26, 2026, 7:28 p.m. πŸ”„ Last Modified: March 27, 2026, 8:33 a.m.
Total resulsts: 341070
Page 42 of 34,107
Β« previous page Β» next page
Filters