6.1

CVSS3.1

CVE-2026-42509 - Apache Wicket: crafted strings can break out of the JavaScript sequence

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

📅 Published: May 6, 2026, 8:34 a.m. 🔄 Last Modified: May 6, 2026, 8:30 p.m.

7.5

CVSS3.1

CVE-2026-43646 - Apache Wicket: crafted URLs can bypass PackageResourceGuard

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 10.9.0, which fixes the issue.

📅 Published: May 6, 2026, 8:31 a.m. 🔄 Last Modified: May 6, 2026, 8:29 p.m.

6.5

CVSS3.1

CVE-2026-43975 - Apache Wicket: Possible malicious path traversal in FolderUploadsFileManager

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file paths, allowing an unauthenticated attacker to write arbitrary files outside the intended upload directory or read files from arbitrary locations on …

📅 Published: May 6, 2026, 8:28 a.m. 🔄 Last Modified: May 6, 2026, 8:29 p.m.

6.6

CVSS3.1

CVE-2026-35255 -

Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The supported versions that is affected is v2.3.2. Easily exploitable vulnerability allows unauthenticated attacker to compromise Oracle Cloud Native Environment Command Line Interfac…

📅 Published: May 6, 2026, 8:05 a.m. 🔄 Last Modified: May 6, 2026, 8:30 p.m.

0.0

CVE-2026-43108 - soc: qcom: pd-mapper: Fix element length in servreg_loc_pfr_req_ei

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pd-mapper: Fix element length in servreg_loc_pfr_req_ei It looks element length declared in servreg_loc_pfr_req_ei for reason not matching servreg_loc_pfr_req's reason field due which we could observe decoding error on…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43104 - drm/vc4: Fix a memory leak in hang state error path

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Fix a memory leak in hang state error path When vc4_save_hang_state() encounters an early return condition, it returns without freeing the previously allocated `kernel_state`, leaking memory. Add the missing kfree() cal…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43098 - nfc: s3fwrn5: allocate rx skb before consuming bytes

In the Linux kernel, the following vulnerability has been resolved: nfc: s3fwrn5: allocate rx skb before consuming bytes s3fwrn82_uart_read() reports the number of accepted bytes to the serdev core. The current code consumes bytes into recv_skb and may already deliver a complete frame before allo…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43085 - netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator When batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send() appends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via nlmsg_put(),…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

0.0

CVE-2026-43081 - net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+

In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ Fix the field masks to match the hardware layout documented in downstream GSI (GSI_V3_0_EE_n_GSI_EE_GENERIC_CMD_*). Notably this fixes a WARN I was seeing when I tried…

📅 Published: May 6, 2026, 7:40 a.m. 🔄 Last Modified: May 6, 2026, 7:40 a.m.

6.1

CVSS3.1

CVE-2026-35254 - OCI CLI 3.77 Vulnerability Allows Unauthenticated File Placement Outside Intended Directory

Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated attacker with network access to compromise Oracle OCI CLI. Successful attacks of this vulnerability can result in Orac…

📅 Published: May 6, 2026, 7:08 a.m. 🔄 Last Modified: May 6, 2026, 8:30 p.m.
Total resulsts: 349182
Page 80 of 34,919
« previous page » next page
Filters