5.3

CVSS4.0

CVE-2026-3968 - AutohomeCorp frostmourne Oracle Nashorn JavaScript ExpressionRule.java scriptEngine.eval code injecโ€ฆ

A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection. The attack can be executed remotโ€ฆ

๐Ÿ“… Published: March 12, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

5.3

CVSS4.0

CVE-2026-3967 - Alfresco Activiti Process Variable Serialization System SerializableType.java createObjectInputStreโ€ฆ

A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization Sysโ€ฆ

๐Ÿ“… Published: March 12, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

5.3

CVSS4.0

CVE-2026-3966 - 648540858 wvp-GB28181-pro IP Address ABLMediaNodeServerService.java getDownloadFilePath server-sideโ€ฆ

A vulnerability was detected in 648540858 wvp-GB28181-pro up to 2.7.4-20260107. Affected by this vulnerability is the function getDownloadFilePath of the file /src/main/java/com/genersoft/iot/vmp/media/abl/ABLMediaNodeServerService.java of the component IP Address Handler. The manipulation of the aโ€ฆ

๐Ÿ“… Published: March 12, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:07 p.m.

8.8

CVSS3.1

CVE-2026-3910 - chromium-browser: Inappropriate implementation in V8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 10:20 p.m.

0.0

CVE-2025-61154 -

Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cause a Denial of Service (DoS) via the function decompress_R2004_section at decode.c.

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 14, 2026, 3:37 a.m.

7.5

CVSS3.1

CVE-2026-25819 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have โ€ฆ

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 7:54 p.m.

9.8

CVSS3.1

CVE-2026-26793 -

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 4:02 p.m.

3.3

CVSS3.1

CVE-2025-70873 - sqlite: SQLite: Information Disclosure via Crafted ZIP File

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 14, 2026, 3:35 a.m.

8.8

CVSS3.1

CVE-2026-25817 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provโ€ฆ

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 7:54 p.m.

9.8

CVSS3.1

CVE-2026-25823 -

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauthenticated Remote Code Execution.

๐Ÿ“… Published: March 12, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 7:54 p.m.
Total resulsts: 338091
Page 58 of 33,810
ยซ previous page ยป next page
Filters