8.8

CVSS3.1

CVE-2026-35093 - Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plu…

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:57 p.m.

6.7

CVSS3.1

CVE-2026-34871 -

An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG).

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

5.1

CVSS3.1

CVE-2025-66442 - mbedtls: Mbed TLS and TF-PSA-Crypto: Information disclosure via compiler-induced timing side channel

In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

7.8

CVSS3.1

CVE-2026-23408 - apparmor: Fix double free of ns_name in aa_replace_profiles()

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_profiles() if ns_name is NULL after 1071 error = aa_unpack(udata, &lh, &ns_name); and if ent->ns_name contains an ns_name in 1089 } else if (ent->ns_name…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:24 p.m.

7.3

CVSS3.1

CVE-2026-30273 -

pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

7.8

CVSS3.1

CVE-2026-23411 - apparmor: fix race between freeing data and fs accessing it

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. However the inode can aand does live beyond that …

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:23 p.m.

5.5

CVSS3.1

CVE-2026-23401 - KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE When installing an emulated MMIO SPTE, do so *after* dropping/zapping the existing SPTE (if it's shadow-present). While commit a54aa15c6bda3 was right …

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:17 p.m.

5.5

CVSS3.1

CVE-2026-23402 - KVM: x86/mmu: Only WARN in direct MMUs when overwriting shadow-present SPTE

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Only WARN in direct MMUs when overwriting shadow-present SPTE Adjust KVM's sanity check against overwriting a shadow-present SPTE with a another SPTE with a different target PFN to only apply to direct MMUs, i.e. on…

πŸ“… Published: April 1, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 3:17 p.m.

5.3

CVSS4.0

CVE-2026-5240 - code-projects BloodBank Managing System admin_state.php cross site scripting

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclo…

πŸ“… Published: March 31, 2026, 11:45 p.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

6.9

CVSS4.0

CVE-2026-5238 - itsourcecode Payroll Management System Parameter view_employee.php sql injection

A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed fr…

πŸ“… Published: March 31, 2026, 11:45 p.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.
Total resulsts: 349182
Page 764 of 34,919
Β« previous page Β» next page
Filters