5.4

CVSS3.1

CVE-2026-4274 - Insufficient authorization in shared channel membership sync grants team-level access instead of ch…

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared…

📅 Published: March 26, 2026, 10:43 a.m. 🔄 Last Modified: March 27, 2026, 9:28 a.m.

7.1

CVSS3.1

CVE-2026-23397 - nfnetlink_osf: validate individual option lengths in fingerprints

In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_…

📅 Published: March 26, 2026, 10:22 a.m. 🔄 Last Modified: April 24, 2026, 3:18 p.m.

6.9

CVSS4.0

CVE-2026-4263 - Incorrect authorization in HiJiffy Chatbot

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter  'visitor' in '/api/v1/webchat/message'.

📅 Published: March 26, 2026, 9:12 a.m. 🔄 Last Modified: March 27, 2026, 8:36 a.m.

6.9

CVSS4.0

CVE-2026-4262 - Incorrect authorization in HiJiffy Chatbot

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' in '/api/v1/download/<ID>/'.

📅 Published: March 26, 2026, 9:06 a.m. 🔄 Last Modified: March 27, 2026, 8:36 a.m.

8.7

CVSS4.0

CVE-2026-4862 - UTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file /goform/formConfigDnsFilterGlobal of the component Parameter Handler. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be …

📅 Published: March 26, 2026, 9 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

8.7

CVSS4.0

CVE-2026-4861 - Wavlink WL-NU516U1 nas.cgi ftext stack-based overflow

A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /cgi-bin/nas.cgi. This manipulation of the argument Content-Length causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to …

📅 Published: March 26, 2026, 8:18 a.m. 🔄 Last Modified: March 30, 2026, 1:26 p.m.

6.9

CVSS4.0

CVE-2026-4860 - 648540858 wvp-GB28181-pro API Endpoint RedisTemplateConfig.java GenericFastJsonRedisSerializer dese…

A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/RedisTemplateConfig.java of the component API Endpoint. The manipulation results in deserialization. It i…

📅 Published: March 26, 2026, 8:18 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.

6.9

CVSS4.0

CVE-2026-4850 - code-projects Simple Laundry System Parameter checkregisitem.php sql injection

A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checkregisitem.php of the component Parameter Handler. The manipulation of the argument Long-arm-shirtVol results in sql injection. The attack may be launched remotely. The e…

📅 Published: March 26, 2026, 7:41 a.m. 🔄 Last Modified: April 3, 2026, 9:18 p.m.

5.3

CVSS4.0

CVE-2026-4849 - code-projects Simple Laundry System Parameter modify.php cross site scripting

A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /modify.php of the component Parameter Handler. The manipulation of the argument firstName leads to cross site scripting. The attack may be initiated remotely. The exploit is publ…

📅 Published: March 26, 2026, 7:41 a.m. 🔄 Last Modified: April 3, 2026, 9:18 p.m.

5.3

CVSS4.0

CVE-2026-4848 - dameng100 muucmf list.html cross site scripting

A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/extend/list.html. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and m…

📅 Published: March 26, 2026, 6:59 a.m. 🔄 Last Modified: April 24, 2026, 4:35 p.m.
Total resulsts: 349182
Page 864 of 34,919
« previous page » next page
Filters