7.1

CVSS3.1

CVE-2026-34379 - OpenEXR has a misaligned write in LossyDctDecoder_execute leading to undefined behavior (DWA/DWAB d…

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_…

📅 Published: April 6, 2026, 3:21 p.m. 🔄 Last Modified: April 7, 2026, 7:04 p.m.

6.5

CVSS3.1

CVE-2026-34378 - OpenEXR has a signed integer overflow in generic_unpack() when parsing EXR files with crafted negat…

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before 3.4.9, a missing bounds check on the dataWindow attribute in EXR file headers allows an attacker to trigger a signed integer overflow…

📅 Published: April 6, 2026, 3:19 p.m. 🔄 Last Modified: April 7, 2026, 7:05 p.m.

5

CVSS3.1

CVE-2026-5704 - Tar: tar: hidden file injection via crafted archives

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files ont…

📅 Published: April 6, 2026, 3:17 p.m. 🔄 Last Modified: April 6, 2026, 3:18 p.m.

8.2

CVSS3.1

CVE-2026-34982 - Vim modeline bypass via various options affects Vim < 9.2.0276

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be exec…

📅 Published: April 6, 2026, 3:16 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-5665 - code-projects Online FIR System Login checklogin.php sql injection

A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to b…

📅 Published: April 6, 2026, 3:15 p.m. 🔄 Last Modified: April 6, 2026, 3:15 p.m.

6.9

CVSS4.0

CVE-2026-34217 - SandboxJS has a Sandbox Escape via Prop Object Leak in New Handler

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sandboxjs. The vulnerability allows untrusted sandboxed code to leak internal interpreter objects through the new operator, exposing sandbox scope objects in the scope hierarchy to un…

📅 Published: April 6, 2026, 3:12 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

6.9

CVSS4.0

CVE-2026-34211 - SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion in the restOfExp function and the lispify/lispifyExpr call chain. An attacker can crash any Node.js process that parses untrusted input by supplying deeply nested expressions (e.…

📅 Published: April 6, 2026, 3:10 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

10

CVSS3.1

CVE-2026-34208 - SandboxJS: Sandbox integrity escape

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject). Because this.construc…

📅 Published: April 6, 2026, 3:09 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

7.5

CVSS3.1

CVE-2026-34148 - Fedify affected by resource exhaustion caused by unbounded redirect following during remote key/doc…

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited…

📅 Published: April 6, 2026, 3:06 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

6.4

CVSS3.1

CVE-2026-33727 - Pi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this is not a direct inter…

📅 Published: April 6, 2026, 3:02 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.
Total resulsts: 343194
Page 72 of 34,320
« previous page » next page
Filters