5.2

CVSS3.1

CVE-2026-24153 -

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

πŸ“… Published: March 31, 2026, 4:23 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

8.3

CVSS3.1

CVE-2026-24148 -

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tamper…

πŸ“… Published: March 31, 2026, 4:22 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

0.0

CVE-2026-5250 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: March 31, 2026, 4:04 p.m. πŸ”„ Last Modified: April 17, 2026, 10:21 p.m.

7.5

CVSS3.1

CVE-2026-5087 - PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes …

PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Middleware::Session::Store::Cookie attempts to read bytes from the /dev/urandom device directly. If that fails (for example, on systems without the device, such as Windows), then it…

πŸ“… Published: March 31, 2026, 4:03 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

9.8

CVSS3.1

CVE-2026-34243 - wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code …

πŸ“… Published: March 31, 2026, 3:49 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

8.2

CVSS4.0

CVE-2026-34219 - libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, …

πŸ“… Published: March 31, 2026, 3:47 p.m. πŸ”„ Last Modified: April 7, 2026, 8:07 a.m.

8.7

CVSS4.0

CVE-2026-5204 - Tenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflow

A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack can be initiated remotely. The exploit …

πŸ“… Published: March 31, 2026, 3:45 p.m. πŸ”„ Last Modified: April 2, 2026, 8:22 p.m.

5.1

CVSS4.0

CVE-2026-5203 - CMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder …

A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulation results in path traversal. It is possible to launch the att…

πŸ“… Published: March 31, 2026, 3:45 p.m. πŸ”„ Last Modified: April 24, 2026, 6:12 p.m.

7.5

CVSS3.1

CVE-2026-34240 - jose vulnerable to untrusted JWK header key acceptance during signature verification

JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could allow an unauthenticated, remote attacker to forge valid JWS/JWT tokens by using a key embedded in the JOSE header (jwk). The vulnerability exists because key selection could t…

πŸ“… Published: March 31, 2026, 3:44 p.m. πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

6.1

CVSS3.1

CVE-2026-34237 - MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 1.0.1 and 1.1.1, there is a hardcoded wildcard CORS vulnerability. This issue has been patched in versions 1.0.1 and 1.1.1.

πŸ“… Published: March 31, 2026, 3:40 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.
Total resulsts: 349182
Page 776 of 34,919
Β« previous page Β» next page
Filters