8.8

CVSS3.1

CVE-2026-36762 -

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 8 p.m.

8.8

CVSS3.1

CVE-2026-36765 -

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 4, 2026, 8 p.m.

3.7

CVSS3.1

CVE-2026-40686 -

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged within an error message produced during handling of an unrelated e-mail message.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 2:27 p.m.

6.5

CVSS3.1

CVE-2026-40685 -

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 2, 2026, 8:15 a.m.

4.8

CVSS3.1

CVE-2026-40687 - Out‑of‑Bounds Write and Data Disclosure via Exim SPA Authentication Driver

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data processing that divulges data from uninitialized heap memory.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 2:25 p.m.

7.8

CVSS3.1

CVE-2026-31786 - Buffer overflow in drivers/xen/sys-hypervisor.c

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor a string. The first causes a buffer overflow as sprintf in buildid_show will read and…

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

7.8

CVSS3.1

CVE-2026-31693 - cifs: some missing initializations on replay

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code where a request can be replayed if necessary. However, some of these places were missing the necessary r…

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: May 3, 2026, 5:45 a.m.

0.0

CVE-2026-36960 -

A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF tokens or strict Origin/Referer validation for administrative API endpoints. An attacker can craft …

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 2:55 p.m.

0.0

CVE-2026-36764 -

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:45 p.m.

0.0

CVE-2026-36760 -

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem locations while chunked upload is enabled.

πŸ“… Published: April 30, 2026, midnight πŸ”„ Last Modified: April 30, 2026, 4:52 p.m.
Total resulsts: 348208
Page 99 of 34,821
Β« previous page Β» next page
Filters