2.4

CVSS3.1

CVE-2026-27308 - ColdFusion | Uncontrolled Resource Consumption (CWE-400)

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of …

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 16, 2026, 2:40 p.m.

7.5

CVSS3.1

CVE-2026-27282 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user…

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 16, 2026, 2:43 p.m.

8.6

CVSS3.1

CVE-2026-27305 - ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outsi…

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 16, 2026, 2:42 p.m.

9.3

CVSS3.1

CVE-2026-27304 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 16, 2026, 2:42 p.m.

8.4

CVSS3.1

CVE-2026-27306 - ColdFusion | Improper Input Validation (CWE-20)

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim m…

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 16, 2026, 2:41 p.m.

2.4

CVSS3.1

CVE-2026-27307 - ColdFusion | Uncontrolled Resource Consumption (CWE-400)

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of …

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 16, 2026, 2:41 p.m.

7.1

CVSS3.1

CVE-2026-33020 - libsixel: Integer Overflow in write_png_to_file() leads to Heap-based Buffer Overflow

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1…

πŸ“… Published: April 14, 2026, 9:53 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

5.4

CVSS3.1

CVE-2026-34213 - Docmost has cross-page attachment overwrite via flawed attachmentId overwrite validation

Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.71.0, improper authorization in Docmost allows a low-privileged authenticated user to overwrite another page's attachment within the same workspace by supplying a victim `attachmen…

πŸ“… Published: April 14, 2026, 9:49 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

7.1

CVSS3.1

CVE-2026-33019 - libsixel: Integer overflow leads to Out-of-bounds Read in img2sixel

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds ch…

πŸ“… Published: April 14, 2026, 9:49 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.

7

CVSS3.1

CVE-2026-33018 - libsixel: Use-After-Free in load_gif()

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditio…

πŸ“… Published: April 14, 2026, 9:45 p.m. πŸ”„ Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 345136
Page 57 of 34,514
Β« previous page Β» next page
Filters