8.8

CVSS3.1

CVE-2026-26794 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request.

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 14, 2026, 3:28 a.m.

9.8

CVSS3.1

CVE-2026-26792 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbi…

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 14, 2026, 3:26 a.m.

9.1

CVSS3.1

CVE-2026-25818 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption paramete…

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 7:54 p.m.

8.8

CVSS3.1

CVE-2026-3909 - chromium-browser: Out of bounds write in Skia

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 13, 2026, 10:20 p.m.

0.0

CVE-2025-61154 -

Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.

πŸ“… Published: March 12, 2026, midnight πŸ”„ Last Modified: March 14, 2026, 3:37 a.m.

5.3

CVSS4.0

CVE-2026-3965 - whyour qinglong API express.ts protection mechanism

A security vulnerability has been detected in whyour qinglong up to 2.20.1. Affected is an unknown function of the file back/loaders/express.ts of the component API Interface. The manipulation of the argument command leads to protection mechanism failure. The attack may be initiated remotely. The e…

πŸ“… Published: March 11, 2026, 11:32 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

6.8

CVSS3.1

CVE-2026-2808 - Consul vulnerable to arbitrary file reads through the vault kubernetes authentication provider

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.

πŸ“… Published: March 11, 2026, 11:08 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

4.8

CVSS4.0

CVE-2026-3964 - OpenAkita Chat API Endpoint shell.py run os command injection

A weakness has been identified in OpenAkita up to 1.24.3. This impacts the function run of the file src/openakita/tools/shell.py of the component Chat API Endpoint. Executing a manipulation of the argument Message can lead to os command injection. The attack is restricted to local execution. The ex…

πŸ“… Published: March 11, 2026, 11:02 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

6.3

CVSS4.0

CVE-2026-3963 - perfree go-fastdfs-web Apache Shiro RememberMe ShiroConfig.java rememberMeManager hard-coded key

A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager of the file src/main/java/com/perfree/config/ShiroConfig.java of the component Apache Shiro RememberMe. Performing a manipulation results in use of hard-coded cryptographic key . …

πŸ“… Published: March 11, 2026, 11:02 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.

6.9

CVSS4.0

CVE-2026-31988 - yauzl 3.2.0 - Denial of Service via Off-by-One Error in NTFS Timestamp Parser

yauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an off-by-one error in the NTFS extended timestamp extra field parser within the getLastModDate() function. The while loop condition checks cursor < data.length + 4 instead of cursor + 4 <= data.length, allowing readUInt16LE()…

πŸ“… Published: March 11, 2026, 10:58 p.m. πŸ”„ Last Modified: March 12, 2026, 9:07 p.m.
Total resulsts: 338058
Page 56 of 33,806
Β« previous page Β» next page
Filters