3.7

CVSS3.1

CVE-2025-31984 - HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or i…

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.

📅 Published: May 6, 2026, 1:44 p.m. 🔄 Last Modified: May 7, 2026, 4:25 p.m.

3.7

CVSS3.1

CVE-2025-31983 - HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to …

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing the risk of cross-site scripting (XSS) and potential exposure of sensitive information.

📅 Published: May 6, 2026, 1:40 p.m. 🔄 Last Modified: May 6, 2026, 11:17 p.m.

7.1

CVSS4.0

CVE-2026-41287 - Stack-based Buffer Overflow in WatchGuard Agent Discovery Service on Windows Causes Denial of Servi…

Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.

📅 Published: May 6, 2026, 1:40 p.m. 🔄 Last Modified: May 6, 2026, 3:16 p.m.

2.6

CVSS3.1

CVE-2025-31957 - HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability.

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

📅 Published: May 6, 2026, 1:37 p.m. 🔄 Last Modified: May 7, 2026, 4:35 p.m.

7.5

CVSS3.1

CVE-2026-40562 - Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence

Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An …

📅 Published: May 6, 2026, 12:36 p.m. 🔄 Last Modified: May 7, 2026, 9:25 p.m.

6.3

CVSS4.0

CVE-2026-8026 - FlowiseAI Flowise API Response account.service.ts login information disclosure

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Response Handler. The manipulation results in information disclosure. The attack can be launched remotely…

📅 Published: May 6, 2026, 12:30 p.m. 🔄 Last Modified: May 7, 2026, 3:04 p.m.

9.1

CVSS3.1

CVE-2026-5081 - Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are ins…

Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_ID environment variable for the session id. The UNIQUE_ID variable is set by the Apache mod_unique_i…

📅 Published: May 6, 2026, 12:16 p.m. 🔄 Last Modified: May 6, 2026, 5:16 p.m.

8.7

CVSS4.0

CVE-2026-6210 - Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A non-marker element (such as a…

📅 Published: May 6, 2026, 11:59 a.m. 🔄 Last Modified: May 6, 2026, 7:30 p.m.

2.7

CVSS3.1

CVE-2025-62345 - HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerabil…

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling implementation, increasing the risk of misconfiguration and operational errors.

📅 Published: May 6, 2026, 11:49 a.m. 🔄 Last Modified: May 7, 2026, 9:25 p.m.

8.8

CVSS3.1

CVE-2025-31951 - HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulne…

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.

📅 Published: May 6, 2026, 11:47 a.m. 🔄 Last Modified: May 7, 2026, 9:25 p.m.
Total resulsts: 349182
Page 78 of 34,919
« previous page » next page
Filters