10

CVSS3.1

CVE-2026-34156 - NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflo…

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODU…

πŸ“… Published: March 31, 2026, 1:33 p.m. πŸ”„ Last Modified: April 21, 2026, 11:30 p.m.

7.2

CVSS4.0

CVE-2026-34155 - RAUC: Improper Signing of Plain Bundles Exceeding 2 GiB

RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only the first few bytes of the payload. Given such a bundle with a legiti…

πŸ“… Published: March 31, 2026, 1:28 p.m. πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

7.8

CVSS3.1

CVE-2026-3308 - CVE-2026-3308

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code executi…

πŸ“… Published: March 31, 2026, 1:13 p.m. πŸ”„ Last Modified: April 21, 2026, 10:16 a.m.

4.8

CVSS3.1

CVE-2026-27854 - Use after free when parsing EDNS options in Lua

An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus triggering a use-after-f…

πŸ“… Published: March 31, 2026, 12:06 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

5.9

CVSS3.1

CVE-2026-27853 - Out-of-bounds write when rewriting large DNS packets

An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet might become larger than the initial response and even exceed 65535 byt…

πŸ“… Published: March 31, 2026, 12:04 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

5.3

CVSS3.1

CVE-2026-24030 - Unbounded memory allocation for DoQ and DoH3

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly close…

πŸ“… Published: March 31, 2026, 12:01 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

6.5

CVSS3.1

CVE-2026-24029 - DNS over HTTPS ACL bypass

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.

πŸ“… Published: March 31, 2026, 11:59 a.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

5.3

CVSS3.1

CVE-2026-24028 - Out-of-bounds read when parsing DNS packets via Lua

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential inf…

πŸ“… Published: March 31, 2026, 11:57 a.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

3.1

CVSS3.1

CVE-2026-0397 - Information disclosure via CORS misconfiguration

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration o…

πŸ“… Published: March 31, 2026, 11:53 a.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

3.1

CVSS3.1

CVE-2026-0396 - HTML injection in the web dashboard

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

πŸ“… Published: March 31, 2026, 11:50 a.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.
Total resulsts: 349182
Page 781 of 34,919
Β« previous page Β» next page
Filters