8.6

CVSS4.0

CVE-2026-6691 - MongoDB C Driver Cyrus SASL Canonicalization Buffer Overflow

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.

πŸ“… Published: May 6, 2026, 3:08 p.m. πŸ”„ Last Modified: May 6, 2026, 3:24 p.m.

6.8

CVSS3.1

CVE-2026-6863 - HTTP Filestore Endpoints Misapply Permissions Across Organizations

Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with only the reader role in the root organization (the lowest authenticated role, holding only READ_RESULTS permission ) can issue a single authenticated HTTP GET that can read any files…

πŸ“… Published: May 6, 2026, 2:50 p.m. πŸ”„ Last Modified: May 6, 2026, 11 p.m.

6.3

CVSS4.0

CVE-2026-8028 - FlowiseAI Flowise Endpoint account.service.ts verify information disclosure

A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possib…

πŸ“… Published: May 6, 2026, 2:15 p.m. πŸ”„ Last Modified: May 7, 2026, 2:47 p.m.

2.6

CVSS3.1

CVE-2025-31975 - HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue w…

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially aiding attackers in targeting known vulnerabilities.

πŸ“… Published: May 6, 2026, 1:51 p.m. πŸ”„ Last Modified: May 7, 2026, 4:33 p.m.

4.6

CVSS3.1

CVE-2025-52613 - HCL BigFix Service Management (SM) is affected by use of a vulnerable component

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

πŸ“… Published: May 6, 2026, 1:50 p.m. πŸ”„ Last Modified: May 7, 2026, 2:59 p.m.

4.8

CVSS3.1

CVE-2025-31976 - HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrated. .

πŸ“… Published: May 6, 2026, 1:49 p.m. πŸ”„ Last Modified: May 7, 2026, 4:30 p.m.

4.6

CVSS3.1

CVE-2025-31978 - HCL BigFix Service Management (SM) does not adequately sanitize or safely render

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when a…

πŸ“… Published: May 6, 2026, 1:48 p.m. πŸ”„ Last Modified: May 7, 2026, 4:26 p.m.

3.5

CVSS3.1

CVE-2025-31959 - HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .

πŸ“… Published: May 6, 2026, 1:47 p.m. πŸ”„ Last Modified: May 7, 2026, 4:35 p.m.

3.7

CVSS3.1

CVE-2025-31982 - HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but cou…

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

πŸ“… Published: May 6, 2026, 1:46 p.m. πŸ”„ Last Modified: May 6, 2026, 11:16 p.m.

5.3

CVSS4.0

CVE-2026-8027 - FlowiseAI Flowise User Controller authorization

A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated r…

πŸ“… Published: May 6, 2026, 1:45 p.m. πŸ”„ Last Modified: May 7, 2026, 2:50 p.m.
Total resulsts: 349182
Page 77 of 34,919
Β« previous page Β» next page
Filters