8.7

CVSS4.0

CVE-2026-33084 - DataEase has SQL Injection through its getFieldEnumObj Endpoint

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied sort value to the s…

πŸ“… Published: April 16, 2026, 6:14 p.m. πŸ”„ Last Modified: April 17, 2026, 2:30 a.m.

6.6

CVSS3.1

CVE-2025-43937 -

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to…

πŸ“… Published: April 16, 2026, 6:03 p.m. πŸ”„ Last Modified: April 16, 2026, 6:03 p.m.

4.4

CVSS3.1

CVE-2025-43935 - Improper Resource Release Causing Denial of Service in Dell PowerScale OneFS

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

πŸ“… Published: April 16, 2026, 5:59 p.m. πŸ”„ Last Modified: April 17, 2026, 3 a.m.

4.1

CVSS3.1

CVE-2025-43883 - Improper Check Enables Denial of Service in Dell PowerScale OneFS

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service.

πŸ“… Published: April 16, 2026, 5:54 p.m. πŸ”„ Last Modified: April 17, 2026, 3 a.m.

8.7

CVSS4.0

CVE-2026-33083 - DataEase has SQL Injection in Order By Clause

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and /de2api/datasetTree/exportDataset. The Order2SQLObj …

πŸ“… Published: April 16, 2026, 5:52 p.m. πŸ”„ Last Modified: April 16, 2026, 5:52 p.m.

8.7

CVSS4.0

CVE-2026-33082 - DataEase: SQL Injection in v2 Dataset Export

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized into a filtering object and passed to WhereTree2S…

πŸ“… Published: April 16, 2026, 5:39 p.m. πŸ”„ Last Modified: April 16, 2026, 5:39 p.m.

7.3

CVSS3.1

CVE-2026-41082 -

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

πŸ“… Published: April 16, 2026, 5:32 p.m. πŸ”„ Last Modified: April 16, 2026, 11 p.m.

1.7

CVSS4.0

CVE-2026-27820 - zlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but…

πŸ“… Published: April 16, 2026, 5:27 p.m. πŸ”„ Last Modified: April 16, 2026, 6:20 p.m.

5.3

CVSS3.1

CVE-2026-24749 - Silverstripe Assets Module has a DBFile::getURL() permission bypass

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which b…

πŸ“… Published: April 16, 2026, 5:08 p.m. πŸ”„ Last Modified: April 16, 2026, 5:08 p.m.

8.7

CVSS4.0

CVE-2026-2336 - Weak webstax_auth Cookie Authentication Allows Privilege Escalation

A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.

πŸ“… Published: April 16, 2026, 5:02 p.m. πŸ”„ Last Modified: April 17, 2026, 3 a.m.
Total resulsts: 344943
Page 5 of 34,495
Β« previous page Β» next page
Filters