7.8

CVSS3.1

CVE-2026-30309 -

InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffective. The predefined blocklist fails to cover native high-risk commands in Windows PowerShell (such as powershell), and the matching algorithm…

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

9

CVSS3.1

CVE-2026-30282 -

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.

7.6

CVSS3.1

CVE-2026-29870 - Agentic Context Engine Arbitrary File Write via Directory Traversal

A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir parameter in OfflineACE.run. The save_to_file method in ace/skillbook.py fails to normalize or validate filesystem paths, allowing traversal sequences t…

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:11 a.m.

8.8

CVSS3.1

CVE-2026-5278 - chromium-browser: Use after free in Web MIDI

Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.

9.8

CVSS3.1

CVE-2026-30314 -

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, …

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

9.8

CVSS3.1

CVE-2026-30286 - Arbitrary File Overwrite in Funambol Zefiro Leads to Remote Code Execution

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

9.8

CVSS3.1

CVE-2026-30278 - Arbitrary File Overwrite Leading to Code Execution in FLY is FUN Aviation Navigation

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 8:08 a.m.

9.8

CVSS3.1

CVE-2026-30285 -

An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 8 p.m.

8.8

CVSS3.1

CVE-2026-5280 - chromium-browser: Use after free in WebCodecs

Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.

6.5

CVSS3.1

CVE-2026-5276 - chromium-browser: Insufficient policy enforcement in WebUSB

Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 31, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 8:18 p.m.
Total resulsts: 349182
Page 791 of 34,919
Β« previous page Β» next page
Filters