5.5

CVSS3.1

CVE-2026-33165 - heap out-of-bounds write in libde265 1.0.16

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay co…

📅 Published: March 20, 2026, 8:32 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.

7.8

CVSS3.1

CVE-2026-33156 - DLL Sideloading in ScreenToGif

ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the Windows System32 directory…

📅 Published: March 20, 2026, 8:29 p.m. 🔄 Last Modified: March 29, 2026, 8:28 p.m.

8.7

CVSS4.0

CVE-2026-33155 - DeepDiff has Memory Exhaustion DoS through SAFE_TO_IMPORT

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _RestrictedUnpickler validates which classes can be loaded but does not limit their constructor arguments. A few of the types in SAFE_TO_IMPORT have const…

📅 Published: March 20, 2026, 8:25 p.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.

7.5

CVSS3.1

CVE-2026-33154 - dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in config…

📅 Published: March 20, 2026, 8:22 p.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.

7.8

CVSS3.1

CVE-2026-33150 - Use After Free in libfuse

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creati…

📅 Published: March 20, 2026, 8:20 p.m. 🔄 Last Modified: March 27, 2026, 9:21 a.m.

5.5

CVSS3.1

CVE-2026-33179 - libfuse: NULL Pointer Dereference and Memory Leak in io_uring Queue Initialization

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer dereference and memory leak in fuse_uring_init_queue allows a local user to crash the FUSE daemon or cause resource exhaustion. When numa_alloc_local fails during io_uring queue e…

📅 Published: March 20, 2026, 8:20 p.m. 🔄 Last Modified: March 29, 2026, 8:28 p.m.

8.7

CVSS4.0

CVE-2026-33151 - socket.io allows an unbounded number of binary attachments

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server r…

📅 Published: March 20, 2026, 8:13 p.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.

7.3

CVSS3.1

CVE-2026-33147 - GMT: Stack-based Buffer Overflow in gmt_remote_dataset_id

GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt_remote_dataset_id function within src/gmt_remote.c. This issue occurs when a specially …

📅 Published: March 20, 2026, 8:10 p.m. 🔄 Last Modified: March 29, 2026, 8:28 p.m.

5.8

CVSS3.1

CVE-2026-33144 - GPAC MP4Box Heap Buffer Overflow Write in gf_xml_parse_bit_sequence_bs (NHML BS Parsing)

GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gf_xml_parse_bit_sequence_bs function in utils/xml_bin_custom.c when processing a crafted NHML file containing mali…

📅 Published: March 20, 2026, 8:07 p.m. 🔄 Last Modified: April 15, 2026, 4:45 p.m.

8.1

CVSS3.1

CVE-2026-33142 - OneUptime: ClickHouse SQL Injection via unvalidated column identifiers in sort, select, and groupBy…

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same validation to three other query cons…

📅 Published: March 20, 2026, 8:05 p.m. 🔄 Last Modified: March 25, 2026, 2:34 p.m.
Total resulsts: 349182
Page 1011 of 34,919
« previous page » next page
Filters