8.5

CVSS4.0

CVE-2026-4416 - GIGABYTE|Performance Library - Insecure Deserialization

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.

📅 Published: March 30, 2026, 7:52 a.m. 🔄 Last Modified: April 9, 2026, 8:29 a.m.

5.8

CVSS4.0

CVE-2026-25704 - Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData

A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greeter can allow an attacker to regain privileges that should have been dropped and abuse them in the racy checking logic. This issue affects cosmic-greeter before https://github.C…

📅 Published: March 30, 2026, 7:44 a.m. 🔄 Last Modified: April 16, 2026, 5:16 p.m.

7.5

CVSS3.1

CVE-2026-5121 - Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arb…

📅 Published: March 30, 2026, 7:44 a.m. 🔄 Last Modified: May 7, 2026, 9:44 p.m.

9.2

CVSS4.0

CVE-2026-4415 - GIGABYTE|Gigabyte Control Center - Arbitrary File Write

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

📅 Published: March 30, 2026, 7:36 a.m. 🔄 Last Modified: April 9, 2026, 8:29 a.m.

5.3

CVSS4.0

CVE-2025-3716 - User enumeration in ESET Protect (on-prem)

User enumeration in ESET Protect (on-prem) via Response Timing.

📅 Published: March 30, 2026, 7:30 a.m. 🔄 Last Modified: March 31, 2026, 8:41 p.m.

9.8

CVSS3.1

CVE-2025-15379 - Command Injection in mlflow/mlflow

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_env.yaml` …

📅 Published: March 30, 2026, 7:16 a.m. 🔄 Last Modified: April 28, 2026, 2:26 p.m.

8.7

CVSS4.0

CVE-2026-3945 - Integer Overflow in Tinyproxy Chunked Transfer Parsing Causes DoS

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol() without properly validati…

📅 Published: March 30, 2026, 7:05 a.m. 🔄 Last Modified: March 31, 2026, 8:41 p.m.

7.5

CVSS3.1

CVE-2026-2328 - Backend Access Due to Insufficient Input Validation

An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.

📅 Published: March 30, 2026, 6:55 a.m. 🔄 Last Modified: March 31, 2026, 8:41 p.m.

5.9

CVSS3.1

CVE-2026-5119 - Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel …

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker or a malicious HTTP proxy can intercept these cookies, leading to potential ses…

📅 Published: March 30, 2026, 5:30 a.m. 🔄 Last Modified: May 6, 2026, 2:52 p.m.

2.3

CVSS4.0

CVE-2026-5107 - FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to h…

📅 Published: March 30, 2026, 5 a.m. 🔄 Last Modified: April 29, 2026, 10:01 p.m.
Total resulsts: 349182
Page 804 of 34,919
« previous page » next page
Filters