7.2

CVSS3.1

CVE-2025-55988 -

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

5.4

CVSS3.1

CVE-2026-33372 -

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due to improper validation of CSRF tokens. The application accepts CSRF tokens supplied within the request body instead of requiring them through the expec…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

5.4

CVSS3.1

CVE-2025-63260 -

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

6.1

CVSS3.1

CVE-2026-29828 -

DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field projectDesc.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

6.5

CVSS3.1

CVE-2026-30579 -

File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 7:59 a.m.

7.5

CVSS3.1

CVE-2025-46597 -

Bitcoin Core 0.13.0 through 29.x has an integer overflow.

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 2, 2026, 8:23 p.m.

7.5

CVSS3.1

CVE-2026-23536 - Feast: unauthenticated arbitrary file read

A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to potentia…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 2:34 p.m.

9.1

CVSS3.1

CVE-2026-23537 - feast: Unauthenticated Arbitrary File Write

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling a…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: March 24, 2026, 10:35 a.m.

5.5

CVSS3.1

CVE-2026-23277 - net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit

In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit teql_master_xmit() calls netdev_start_xmit(skb, slave) to transmit through slave devices, but does not update skb->dev to the slave device beforeha…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.

7.8

CVSS3.1

CVE-2026-23274 - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels IDLETIMER revision 0 rules reuse existing timers by label and always call mod_timer() on timer->timer. If the label was created first by revision 1 with XT_IDLETIM…

πŸ“… Published: March 20, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.
Total resulsts: 348551
Page 968 of 34,856
Β« previous page Β» next page
Filters