6.9

CVSS4.0

CVE-2026-6129 - zhayujie chatgpt-on-wechat CowAgent Agent Mode Service missing authentication

A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The prโ€ฆ

๐Ÿ“… Published: April 12, 2026, 7:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 3:25 p.m.

4

CVSS3.1

CVE-2026-40396 - varnish: Varnish Cache: Denial of Service via workspace overflow during HTTP/1 pipelining

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough until the session releases its worker thread (timeout_linger) and resume traffic before the session is closed (timeout_โ€ฆ

๐Ÿ“… Published: April 12, 2026, 7:23 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:36 p.m.

4

CVSS3.1

CVE-2026-40395 -

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() function from vmod_headerplus updates the underlying req0, which is normally the original read-only request from which req is derived (readable and writableโ€ฆ

๐Ÿ“… Published: April 12, 2026, 7:21 p.m. ๐Ÿ”„ Last Modified: April 12, 2026, 7:24 p.m.

4

CVSS3.1

CVE-2026-40394 - Varnish Cache: Varnish Enterprise: Varnish Cache and Varnish Enterprise: Denial of Service via workโ€ฆ

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurโ€ฆ

๐Ÿ“… Published: April 12, 2026, 7:17 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:36 p.m.

8.1

CVSS3.1

CVE-2026-40393 -

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

๐Ÿ“… Published: April 12, 2026, 6:49 p.m. ๐Ÿ”„ Last Modified: April 12, 2026, 6:56 p.m.

4

CVSS3.1

CVE-2026-40386 - libexif: libexif: Denial of Service and information disclosure via integer underflow in MakerNote dโ€ฆ

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

๐Ÿ“… Published: April 12, 2026, 6:19 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 8:43 p.m.

4

CVSS3.1

CVE-2026-40385 - libexif: libexif: Information disclosure and crashes via integer overflow in Nikon MakerNote handliโ€ฆ

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

๐Ÿ“… Published: April 12, 2026, 6:16 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 8:15 p.m.

7.1

CVSS4.0

CVE-2019-25713 - MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter

MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blinโ€ฆ

๐Ÿ“… Published: April 12, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 13, 2026, 5:28 p.m.

6.9

CVSS4.0

CVE-2019-25712 - BlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration Key

BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registratioโ€ฆ

๐Ÿ“… Published: April 12, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 13, 2026, 6:16 p.m.

6.9

CVSS4.0

CVE-2019-25711 - SpotFTP Password Recover 2.4.2 Denial of Service via Name Field

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash wโ€ฆ

๐Ÿ“… Published: April 12, 2026, 12:28 p.m. ๐Ÿ”„ Last Modified: April 12, 2026, 12:28 p.m.
Total resulsts: 344718
Page 75 of 34,472
ยซ previous page ยป next page
Filters