8.7

CVSS4.0

CVE-2026-33151 - socket.io allows an unbounded number of binary attachments

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server rโ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:13 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 4:45 p.m.

7.3

CVSS3.1

CVE-2026-33147 - GMT: Stack-based Buffer Overflow in gmt_remote_dataset_id

GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt_remote_dataset_id function within src/gmt_remote.c. This issue occurs when a specially โ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:10 p.m. ๐Ÿ”„ Last Modified: March 29, 2026, 8:28 p.m.

5.8

CVSS3.1

CVE-2026-33144 - GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing)

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c when processing a crafted NHML file containing maliโ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 4:45 p.m.

8.1

CVSS3.1

CVE-2026-33142 - OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupByโ€ฆ

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same validation to three other query consโ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:05 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:34 p.m.

8.7

CVSS4.0

CVE-2026-33143 - OneUptime: WhatsApp Webhook Missing Signature Verification

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticaโ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:05 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:34 p.m.

5.3

CVSS4.0

CVE-2026-4505 - eosphoros-ai DB-GPT FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload

A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted upload. It is possibleโ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:02 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:32 p.m.

6.9

CVSS4.0

CVE-2026-4504 - eosphoros-ai db-gpt Incomplete Fix editor sql injection

A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/editor/ of the component Incomplete Fix. This manipulation causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The โ€ฆ

๐Ÿ“… Published: March 20, 2026, 8:02 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2026-33140 - PySpector: Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and prior are affected by a stored Cross-Site Scripting (XSS) vulnerability in the HTML report generator. When PySpector scans a Python file containing JavaSโ€ฆ

๐Ÿ“… Published: March 20, 2026, 8 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:34 p.m.

8.3

CVSS4.0

CVE-2026-33139 - PySpector: Plugin Sandbox Bypass leads to Arbitrary Code Execution

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and prior are affected by a security validation bypass in the plugin system. The validate_plugin_code() function in plugin_system.py, performs static AST anaโ€ฆ

๐Ÿ“… Published: March 20, 2026, 7:59 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:34 p.m.

5.4

CVSS3.1

CVE-2026-4438 - gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

๐Ÿ“… Published: March 20, 2026, 7:59 p.m. ๐Ÿ”„ Last Modified: April 8, 2026, 8:01 p.m.
Total resulsts: 348625
Page 956 of 34,863
ยซ previous page ยป next page
Filters