5.3

CVSS4.0

CVE-2026-5319 - itsourcecode Payroll Management System navbar.php cross site scripting

A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed…

πŸ“… Published: April 2, 2026, 2:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-5318 - LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. T…

πŸ“… Published: April 2, 2026, 1:45 a.m. πŸ”„ Last Modified: April 7, 2026, 12:16 p.m.

5.3

CVSS4.0

CVE-2026-5317 - Nothings stb stb_vorbis.c start_decoder out-of-bounds write

A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The ve…

πŸ“… Published: April 2, 2026, 12:45 a.m. πŸ”„ Last Modified: April 30, 2026, 8:28 p.m.

5.4

CVSS3.1

CVE-2026-1243 - IBM Content Navigator is affected by , a Cross-Site Scripting (XSS) vulnerability

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: April 2, 2026, 12:14 a.m. πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

5.3

CVSS4.0

CVE-2026-5316 - Nothings stb stb_vorbis.c setup_free allocation of resources

A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor …

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 8:31 p.m.

7.8

CVSS3.1

CVE-2026-23415 - futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy()

In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During futex_key_to_node_opt() execution, vma->vm_policy is read under speculative mmap lock and RCU. Concurrently, mbind() may call vma_replace_policy() whi…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:22 p.m.

9.9

CVSS3.1

CVE-2026-25212 - Internal superuser privileges enable remote code execution in Percona PMM 3.6.x

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admin rights can abuse the "Add data source" feature to break out of the database context and execute shell commands on the underlying operating system.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 12:33 a.m.

6.1

CVSS3.1

CVE-2026-30252 - Reflected Cross‑Site Scripting in Interzen ZenShare Suite 17.0 Login Endpoint

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

7.5

CVSS3.1

CVE-2026-34876 -

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation o…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:56 p.m.

6.8

CVSS3.1

CVE-2026-30603 - Root Access via Crafted Firmware Update Script on Qianniao QN-L23PA0904

An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, and exfiltrate data via supplying a crafted iu.sh script contained in an SD card.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.
Total resulsts: 349182
Page 741 of 34,919
Β« previous page Β» next page
Filters