7.5

CVSS3.1

CVE-2026-22743 - Server-Side Request Forgery via Filter Expression Keys in Neo4jVectorStore

Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimited …

📅 Published: March 27, 2026, 5:33 a.m. 🔄 Last Modified: April 16, 2026, 8:23 p.m.

8.6

CVSS3.1

CVE-2026-22742 - Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests…

📅 Published: March 27, 2026, 5:27 a.m. 🔄 Last Modified: April 16, 2026, 8:20 p.m.

6.9

CVSS4.0

CVE-2026-33366 -

Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.

📅 Published: March 27, 2026, 5:25 a.m. 🔄 Last Modified: April 2, 2026, 7:55 a.m.

8.6

CVSS4.0

CVE-2026-33280 -

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

📅 Published: March 27, 2026, 5:25 a.m. 🔄 Last Modified: April 2, 2026, 7:55 a.m.

8.7

CVSS4.0

CVE-2026-32678 -

Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.

📅 Published: March 27, 2026, 5:25 a.m. 🔄 Last Modified: April 2, 2026, 7:55 a.m.

8.7

CVSS4.0

CVE-2026-32669 -

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.

📅 Published: March 27, 2026, 5:24 a.m. 🔄 Last Modified: April 2, 2026, 7:55 a.m.

8.6

CVSS4.0

CVE-2026-27650 - OS Command Injection in Buffalo Wi‑Fi Router Firmware

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.

📅 Published: March 27, 2026, 5:24 a.m. 🔄 Last Modified: April 2, 2026, 7:55 a.m.

9.8

CVSS3.1

CVE-2026-22738 - SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression ke…

📅 Published: March 27, 2026, 5:21 a.m. 🔄 Last Modified: April 18, 2026, 9:45 a.m.

5.1

CVSS4.0

CVE-2026-33559 - XSS Vulnerability in WordPress OpenStreetMap Plugin Allows Script Injection

WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim user acces…

📅 Published: March 27, 2026, 4:56 a.m. 🔄 Last Modified: March 30, 2026, 1:26 p.m.

5.9

CVSS3.1

CVE-2026-34353 - ocaml: OCaml: Information disclosure via integer overflow in Bigarray.reshape

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

📅 Published: March 27, 2026, 4:55 a.m. 🔄 Last Modified: April 14, 2026, 6:43 p.m.
Total resulsts: 349182
Page 837 of 34,919
« previous page » next page
Filters