8.7

CVSS4.0

CVE-2026-3321 - Authorization Bypass in ON24 Q&A chat

A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may…

πŸ“… Published: March 30, 2026, 1:17 p.m. πŸ”„ Last Modified: April 1, 2026, 2:24 p.m.

7.1

CVSS4.0

CVE-2026-4315 - WatchGuard Firebox Cross-Site Request Forgery (CSRF) in Fireware Web UI

A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.This issue affects Fireware OS: 1…

πŸ“… Published: March 30, 2026, 12:38 p.m. πŸ”„ Last Modified: March 31, 2026, 8:40 p.m.

8.4

CVSS4.0

CVE-2026-4266 - WatchGuard Firebox Insecure Deserialization in Fireware Access Portal

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.This issue affects Fireware OS: 12.1 through 12.11.8 and 2025.1 th…

πŸ“… Published: March 30, 2026, 12:38 p.m. πŸ”„ Last Modified: March 31, 2026, 8:40 p.m.

6.7

CVSS3.1

CVE-2026-5165 - Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset

A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage memory, resulting in a use-after-free vulnerability. This issue could allow a local attacker to corrupt system memory, potentially leading to system inst…

πŸ“… Published: March 30, 2026, 12:34 p.m. πŸ”„ Last Modified: April 28, 2026, 2:17 p.m.

6.7

CVSS3.1

CVE-2026-5164 - Virtio-win: virtio-win: denial of service via unvalidated descriptor count in unmap request

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. …

πŸ“… Published: March 30, 2026, 12:34 p.m. πŸ”„ Last Modified: April 28, 2026, 2:22 p.m.

6.9

CVSS4.0

CVE-2019-25655 - Device Monitoring Studio 8.10.00.8925 Denial of Service

Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing re…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

8.7

CVSS4.0

CVE-2019-25654 - Core FTP/SFTP Server 1.2 Denial of Service via Buffer Overflow

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an applicatio…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

6.9

CVSS4.0

CVE-2019-25653 - Navicat for Oracle 12.1.15 Password Field Denial of Service

Navicat for Oracle 12.1.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the password field. Attackers can paste a buffer of 550 repeated characters into the password parameter during Oracle connection conf…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

6.9

CVSS4.0

CVE-2018-25235 - NetworkActiv Web Server 4.0 Username Field Buffer Overflow DoS

NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding t…

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.

6.9

CVSS4.0

CVE-2018-25234 - SmartFTP Client 9.0.2615.0 Denial of Service via Host Field

SmartFTP Client 9.0.2615.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can paste a buffer of 300 repeated characters into the Host connection parameter to trigger an application …

πŸ“… Published: March 30, 2026, 11:02 a.m. πŸ”„ Last Modified: April 8, 2026, 8 p.m.
Total resulsts: 349182
Page 802 of 34,919
Β« previous page Β» next page
Filters