4.8

CVSS4.0

CVE-2026-4816 - Reflected Cross Site Scripting (XSS) vulnerability in Support Board

A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the 'search' parameter in '/supportboard/include/articles.php'. This vuln…

📅 Published: March 25, 2026, 1:31 p.m. 🔄 Last Modified: March 27, 2026, 9:47 a.m.

7.5

CVSS3.1

CVE-2026-3104 - Memory leak in code preparing DNSSEC proofs of non-existence

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46…

📅 Published: March 25, 2026, 1:29 p.m. 🔄 Last Modified: March 26, 2026, 11:43 a.m.

7.5

CVSS3.1

CVE-2026-1519 - Excessive NSEC3 iterations cause high CPU load during insecure delegation validation

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org…

📅 Published: March 25, 2026, 1:25 p.m. 🔄 Last Modified: April 13, 2026, 10:16 a.m.

8.5

CVSS4.0

CVE-2025-40842 - Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerab…

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exploited, can lead to unauthorized disclosure and modification of certain information.

📅 Published: March 25, 2026, 1:10 p.m. 🔄 Last Modified: March 27, 2026, 8:26 p.m.

5.1

CVSS4.0

CVE-2025-40841 - Ericsson Indoor Connect 8855 - Cross-Site Request Forgery Vulnerability

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which, if exploited, can lead to unauthorized modification of certain information.

📅 Published: March 25, 2026, 1:07 p.m. 🔄 Last Modified: March 29, 2026, 8:28 p.m.

8.5

CVSS4.0

CVE-2026-28529 - cryptodev-linux <= 1.14 get_userbuf Use After Free LPE

cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of co…

📅 Published: March 25, 2026, 1 p.m. 🔄 Last Modified: March 26, 2026, 11:43 a.m.

7.2

CVSS4.0

CVE-2025-27260 - Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability

Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability which, if exploited, can lead to unauthorized modification of certain information

📅 Published: March 25, 2026, 12:54 p.m. 🔄 Last Modified: March 29, 2026, 8:28 p.m.

3.3

CVSS4.0

CVE-2026-4761 - Unnecessary permissions on private keys of certificates installed by Network and Security Wizard

When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update P…

📅 Published: March 25, 2026, 12:45 p.m. 🔄 Last Modified: April 2, 2026, 7:59 a.m.

7.7

CVSS4.0

CVE-2026-4760 - Potential unauthorized access to files on the Web HMI server host

From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if these files are accessible to the Servin process execution account. * Installations based on Panorama Suite 2022-SP1 (22.50.005) are vulnerable unless update PS-2210-02-4079 (o…

📅 Published: March 25, 2026, 12:29 p.m. 🔄 Last Modified: March 26, 2026, 12:13 p.m.

7.5

CVSS3.1

CVE-2026-3608 - Stack overflow in Kea daemons

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error. This issue affects Kea versions 2.6.0 through 2.6.4 and 3.0.0 through 3.0.2.

📅 Published: March 25, 2026, 8:46 a.m. 🔄 Last Modified: March 26, 2026, 11:51 a.m.
Total resulsts: 349182
Page 909 of 34,919
« previous page » next page
Filters