8.7

CVSS3.1

CVE-2026-28367 - Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, pot…

πŸ“… Published: March 27, 2026, 4:13 p.m. πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

8.7

CVSS3.1

CVE-2026-28368 - Undertow: undertow: request smuggling via inconsistent header parsing

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, poten…

πŸ“… Published: March 27, 2026, 4:13 p.m. πŸ”„ Last Modified: April 8, 2026, 8:29 a.m.

7.1

CVSS4.0

CVE-2026-33767 - AVideo has SQL Injection via Partial Prepared Statement β€” videos_id Concatenated Directly into Query

WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) for `users_id` but directly concatenates `$this->videos_id` into the query string without parameteriz…

πŸ“… Published: March 27, 2026, 4:12 p.m. πŸ”„ Last Modified: March 31, 2026, 8:01 p.m.

8.7

CVSS4.0

CVE-2026-4961 - Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow

A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack is possible to…

πŸ“… Published: March 27, 2026, 4:09 p.m. πŸ”„ Last Modified: March 31, 2026, 8:01 p.m.

8.7

CVSS4.0

CVE-2026-4960 - Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely.…

πŸ“… Published: March 27, 2026, 4:09 p.m. πŸ”„ Last Modified: April 2, 2026, 7:55 a.m.

5.3

CVSS4.0

CVE-2023-7340 - Wazuh authd service (os_auth) Heap-based Buffer Overflow

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low availability impact to the authe…

πŸ“… Published: March 27, 2026, 3:52 p.m. πŸ”„ Last Modified: March 31, 2026, 8:01 p.m.

6.9

CVSS4.0

CVE-2026-32983 - SSL/TLS Renegotiation DoS in Wazuh Manager authd service

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack …

πŸ“… Published: March 27, 2026, 3:44 p.m. πŸ”„ Last Modified: May 8, 2026, 2:28 p.m.

6.9

CVSS4.0

CVE-2026-4959 - OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument interaction_id results in missing authentication. Remote exploi…

πŸ“… Published: March 27, 2026, 3:31 p.m. πŸ”„ Last Modified: March 31, 2026, 3:09 p.m.

2.3

CVSS4.0

CVE-2026-4958 - OpenBMB XAgent WebSocket Endpoint replayer.py ReplayServer.send_data authorization

A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.send_data of the file XAgentServer/application/websockets/replayer.py of the component WebSocket Endpoint. Such manipulation of the argument interaction_id leads to authorization b…

πŸ“… Published: March 27, 2026, 3:31 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

5.3

CVSS4.0

CVE-2026-32984 - Heap buffer overflow in wazuh-authd

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low availability impact to the authe…

πŸ“… Published: March 27, 2026, 3:02 p.m. πŸ”„ Last Modified: March 31, 2026, 8:01 p.m.
Total resulsts: 349182
Page 830 of 34,919
Β« previous page Β» next page
Filters