0.0

CVE-2025-56537 -

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 3:47 p.m.

0.0

CVE-2026-38992 -

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:30 p.m.

0.0

CVE-2026-37555 -

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before bei…

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 3:48 p.m.

0.0

CVE-2025-56534 -

A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 3:54 p.m.

0.0

CVE-2025-56536 -

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 3:50 p.m.

0.0

CVE-2026-38993 -

Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within the uploads directory or overwrite assets with malicious versions.

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:37 p.m.

0.0

CVE-2026-38991 -

Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This allows an authenticated attacker to rename arbitrary files with the .php file extension enabling arbitrary code …

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 2:32 p.m.

0.0

CVE-2025-50328 -

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alternate dat…

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, 8:02 p.m.

6.5

CVSS3.1

CVE-2026-5545 - curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse

A flaw was found in libcurl. An application using libcurl that performs an authenticated HTTP(S) request after a Negotiate-authenticated one to the same host may incorrectly reuse the previous connection. This authentication bypass vulnerability allows the second request to be sent over a connectio…

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, midnight

5.3

CVSS3.1

CVE-2026-4873 - curl: curl: Information disclosure due to incorrect TLS connection reuse

A flaw was found in curl. A remote attacker could exploit this by initiating an unencrypted connection (via IMAP, SMTP, or POP3) and then making a subsequent request to the same host that requires Transport Layer Security (TLS). Due to incorrect connection reuse, the subsequent request would bypass…

πŸ“… Published: April 29, 2026, midnight πŸ”„ Last Modified: April 29, 2026, midnight
Total resulsts: 347821
Page 75 of 34,783
Β« previous page Β» next page
Filters