7.8

CVSS3.1

CVE-2025-33247 -

NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

πŸ“… Published: March 24, 2026, 8:23 p.m. πŸ”„ Last Modified: March 26, 2026, 12:18 p.m.

5.9

CVSS3.1

CVE-2025-33242 - MCU Registry Modification Leading to Denial of Service and Data Tampering in NVIDIA B300

NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registries, causing a bad state. A successful exploit of this vulnerability might lead to denial of service and data tampering.

πŸ“… Published: March 24, 2026, 8:22 p.m. πŸ”„ Last Modified: March 25, 2026, 8:57 p.m.

6.8

CVSS3.1

CVE-2025-33216 - Buffer Size Miscalculation in NVIDIA SNAP‑4 Container Leading to Denial of Service

NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an incorrect calculation of buffer size by sending crafted configurations. A successful exploit of this vulnerability may lead to crash of the SNAP service, causing denial of service …

πŸ“… Published: March 24, 2026, 8:21 p.m. πŸ”„ Last Modified: March 25, 2026, 8:57 p.m.

6.8

CVSS3.1

CVE-2025-33215 - VIRTIO-BLK Out-of-Range Pointer Offsets Cause Storage Denial of Service in NVIDIA SNAP-4 Container

NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the availability of stor…

πŸ“… Published: March 24, 2026, 8:21 p.m. πŸ”„ Last Modified: March 25, 2026, 8:57 p.m.

6.3

CVSS3.1

CVE-2026-21790 - HCL Traveler is susceptible to a weak default HTTP header validation vulnerability

HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.

πŸ“… Published: March 24, 2026, 8:04 p.m. πŸ”„ Last Modified: March 25, 2026, 8:57 p.m.

4.3

CVSS3.1

CVE-2026-21783 - HCL Traveler is affected by sensitive information disclosure

HCL Traveler is affected by sensitive information disclosure.Β  The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.Β  Attackers could exploit this in…

πŸ“… Published: March 24, 2026, 7:48 p.m. πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

5.6

CVSS3.1

CVE-2026-33412 - Vim affected by Command injection via newline in glob()

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This …

πŸ“… Published: March 24, 2026, 7:43 p.m. πŸ”„ Last Modified: March 26, 2026, 12:18 p.m.

7.1

CVSS4.0

CVE-2026-33353 - Soft Serve: Authenticated repo import can clone server-local private repositories

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This …

πŸ“… Published: March 24, 2026, 7:39 p.m. πŸ”„ Last Modified: March 26, 2026, 12:18 p.m.

5.9

CVSS3.1

CVE-2026-33349 - fast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluati…

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a deve…

πŸ“… Published: March 24, 2026, 7:35 p.m. πŸ”„ Last Modified: March 27, 2026, 9:20 a.m.

6.5

CVSS3.1

CVE-2026-33345 - solidtime vulnerable to IDOR in private projects

solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index(…

πŸ“… Published: March 24, 2026, 7:30 p.m. πŸ”„ Last Modified: March 27, 2026, 9:20 a.m.
Total resulsts: 349182
Page 935 of 34,919
Β« previous page Β» next page
Filters