5.5

CVSS3.1

CVE-2026-23409 - apparmor: fix differential encoding verification

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification Differential encoding allows loops to be created if it is abused. To prevent this the unpack should verify that a diff-encode chain terminates. Unfortunately the differential enco…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:23 p.m.

4.7

CVSS3.1

CVE-2025-67807 -

The login mechanism of Sage DPW 2025_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behaviour in newer versions.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.

8.4

CVSS3.1

CVE-2026-30291 - Arbitrary File Overwrite in Ora Tools PDF Reader Leading to Code Execution

An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:11 p.m.

5.4

CVSS3.1

CVE-2026-29598 - Stored XSS in Acora CMS User Submission Endpoint

Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora CMS v10.7.1 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the First Name and Last Name parameters.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:11 p.m.

5.5

CVSS3.1

CVE-2026-23405 - apparmor: fix: limit the number of levels of policy namespaces

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix: limit the number of levels of policy namespaces Currently the number of policy namespaces is not bounded relying on the user namespace limit. However policy namespaces aren't strictly tied to user namespaces and it…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 6:40 p.m.

6.1

CVSS3.1

CVE-2026-30526 -

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerability is located in the login page, specifically within the msg parameter. The application reflects the content of the msg parameter back to the user without proper HTML encoding or…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:59 p.m.

3.7

CVSS3.1

CVE-2025-67806 - Account Enumeration via Username Disclosure in Sage DPW

The login mechanism of Sage DPW 2021_06_004 displays distinct responses for valid and invalid usernames, allowing enumeration of existing accounts in versions before 2021_06_000. On-premise administrators can toggle this behavior in newer versions.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

9.8

CVSS3.1

CVE-2026-34875 - mbedtls: Mbed TLS and TF-PSA-Crypto: Arbitrary code execution due to buffer overflow in FFDH key ex…

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

7.5

CVSS3.1

CVE-2026-30573 -

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:59 p.m.

9.1

CVSS3.1

CVE-2026-34872 - mbedtls: Mbed TLS and TF-PSA-Crypto: Shared secret manipulation via improper FFDH input validation

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.
Total resulsts: 349182
Page 762 of 34,919
Β« previous page Β» next page
Filters