8.3

CVSS3.1

CVE-2026-33243 - barebox: FIT Signature Verification Bypass Vulnerability

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a…

📅 Published: March 20, 2026, 10:51 p.m. 🔄 Last Modified: March 27, 2026, 9:21 a.m.

9.6

CVSS3.1

CVE-2026-21732 - GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. A…

📅 Published: March 20, 2026, 10:48 p.m. 🔄 Last Modified: April 22, 2026, 6:15 a.m.

6.9

CVSS4.0

CVE-2026-28204 - CTEK Chargeportal Insufficiently Protected Credentials

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

📅 Published: March 20, 2026, 10:47 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.

8.1

CVSS3.1

CVE-2026-33236 - NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processing remote XML index…

📅 Published: March 20, 2026, 10:47 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.

6.9

CVSS4.0

CVE-2026-27649 - CTEK Chargeportal Insufficient Session Expiration

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connect…

📅 Published: March 20, 2026, 10:46 p.m. 🔄 Last Modified: May 6, 2026, 3:16 p.m.

7.5

CVSS3.1

CVE-2026-33231 - NLTK has unauthenticated remote shutdown in nltk.app.wordnet_app

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server …

📅 Published: March 20, 2026, 10:45 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.

8.7

CVSS4.0

CVE-2026-31904 - CTEK Chargeportal Improper Restriction of Excessive Authentication Attempts

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain un…

📅 Published: March 20, 2026, 10:45 p.m. 🔄 Last Modified: May 6, 2026, 3:06 p.m.

6.1

CVSS3.1

CVE-2026-33230 - nltk Vulnerable to Cross-site Scripting

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `lookup_...` route. A cra…

📅 Published: March 20, 2026, 10:43 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.

9.3

CVSS4.0

CVE-2026-25192 - CTEK Chargeportal Missing Authentication for Critical Function

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then i…

📅 Published: March 20, 2026, 10:42 p.m. 🔄 Last Modified: May 6, 2026, 3:19 p.m.

4.8

CVSS4.0

CVE-2026-32810 - Halloy has insecure file permissions on credential files

Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in `0644` on files and `0755` on directories. This allows any…

📅 Published: March 20, 2026, 10:40 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.
Total resulsts: 348641
Page 954 of 34,865
« previous page » next page
Filters