7.1

CVSS4.0

CVE-2026-32937 - free5GC CHF has Out-of-Bounds Slice Access that Leads to DoS

free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerability in the CHF `nchf-convergedcharging` service. A valid authenticated request to PUT `/nchf-convergedcharging/v3/recharging/:ueId?ratingGroup=...` can trigger a server-side pan…

πŸ“… Published: March 20, 2026, 2:43 a.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

9.1

CVSS3.1

CVE-2026-32891 - Anchorr Privilege Escalation: Jellyseerr User β†’ Anchorr Admin via Stored XSS

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary JavaScript in the An…

πŸ“… Published: March 20, 2026, 2:38 a.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

7.5

CVSS3.1

CVE-2026-32933 - AutoMapper Vulnerable to Denial of Service (DoS) via Uncontrolled Recursion

AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a Denial of Service (DoS) attack. When mapping deeply nested object graphs, the library uses recursive method calls without enforcing a default maximum depth limit. This allows an at…

πŸ“… Published: March 20, 2026, 2:38 a.m. πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

9.7

CVSS3.1

CVE-2026-32890 - Anchorr: Stored XSS in User Mapping dropdown allows unprivileged Discord users to exfiltrate all se…

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the con…

πŸ“… Published: March 20, 2026, 2:35 a.m. πŸ”„ Last Modified: March 27, 2026, 8:26 p.m.

5.1

CVSS4.0

CVE-2026-4467 - Comfast CF-AC100 mbox-config command injection

A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=wireless_device_dissoc. The manipulation results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.…

πŸ“… Published: March 20, 2026, 2:32 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

9.8

CVSS3.1

CVE-2026-21992 - Unauthenticated Remote Code Execution via HTTP in Oracle Identity Manager and Web Services Manager

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploit…

πŸ“… Published: March 20, 2026, 2:24 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

6.5

CVSS3.1

CVE-2026-32889 - tinytag: Denial of Service via non-terminating SYLT frame parsing loop

tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files for parsing to trigger a non-terminating loop while the library parses an ID3v2 SYLT (synchronized lyrics) frame. In server-side deployments that automatically parse attacker-suppl…

πŸ“… Published: March 20, 2026, 2:23 a.m. πŸ”„ Last Modified: March 30, 2026, 8:58 p.m.

8.8

CVSS3.1

CVE-2026-32888 - Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search feature is enabled (search_custom filter), user-supplied input from the search GET par…

πŸ“… Published: March 20, 2026, 2:14 a.m. πŸ”„ Last Modified: April 9, 2026, 8:29 a.m.

8

CVSS3.1

CVE-2026-32813 - Admidio: Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layouts, storing user-supplied column names, sort dire…

πŸ“… Published: March 20, 2026, 2:09 a.m. πŸ”„ Last Modified: March 25, 2026, 2:09 p.m.

5.1

CVSS4.0

CVE-2026-4466 - Comfast CF-AC100 mbox-config command injection

A vulnerability has been found in Comfast CF-AC100 2.6.0.8. This affects an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and…

πŸ“… Published: March 20, 2026, 2:02 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.
Total resulsts: 349182
Page 1027 of 34,919
Β« previous page Β» next page
Filters