9.3

CVSS3.1

CVE-2026-33875 - Authenticator Vulnerable to Authentication Flow Hijack

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gemati…

📅 Published: March 27, 2026, 8:25 p.m. 🔄 Last Modified: April 3, 2026, 4:16 p.m.

7.8

CVSS3.1

CVE-2026-33874 - Authenticator vulnerable to Remote Code Execution

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authe…

📅 Published: March 27, 2026, 8:23 p.m. 🔄 Last Modified: April 21, 2026, 7:16 p.m.

8.7

CVSS4.0

CVE-2026-34046 - Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` helper in `src/backend/base/langflow/api/v1/flows.py` branched on the `AUTO_LOGIN` setting to decide whether to filter by `user_id`. When `AUTO_LOGIN` was `False` (i.e., authentic…

📅 Published: March 27, 2026, 8:06 p.m. 🔄 Last Modified: April 1, 2026, 3:55 a.m.

9.3

CVSS4.0

CVE-2026-33873 - Langflow has Authenticated Code Execution in Agentic Assistant Validation

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to validate generated component code, the implementat…

📅 Published: March 27, 2026, 8:04 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

7.1

CVSS4.0

CVE-2026-33872 - elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Con…

elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerabili…

📅 Published: March 27, 2026, 8:01 p.m. 🔄 Last Modified: March 30, 2026, 6:58 p.m.

8.7

CVSS4.0

CVE-2026-33871 - Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CO…

📅 Published: March 27, 2026, 7:55 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2026-33870 - Netty: HTTP Request Smuggling via Chunked Extension Quoted-String Parsing

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix …

📅 Published: March 27, 2026, 7:54 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

8.7

CVSS4.0

CVE-2026-4975 - Tenda AC15 POST Request setcfm formSetCfm memory corruption

A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has bee…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: April 3, 2026, 9:17 p.m.

8.7

CVSS4.0

CVE-2026-4974 - Tenda AC7 POST Request SetSysTimeCfg fromSetSysTime memory corruption

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to launch the attack r…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: March 31, 2026, 1:54 p.m.

5.1

CVSS4.0

CVE-2026-4973 - SourceCodester Online Quiz System add-question.php cross site scripting

A vulnerability was detected in SourceCodester Online Quiz System up to 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-question.php. Performing a manipulation of the argument quiz_question results in cross site scripting. It is possible to initiate the atta…

📅 Published: March 27, 2026, 7:52 p.m. 🔄 Last Modified: April 24, 2026, 4:36 p.m.
Total resulsts: 349182
Page 824 of 34,919
« previous page » next page
Filters