7.8

CVSS3.1

CVE-2026-23271 - perf: Fix __perf_event_overflow() vs perf_remove_from_context() race

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() runs with IRQs disabled for all possible callchains. Specifically the software events can end up running it with only preโ€ฆ

๐Ÿ“… Published: March 20, 2026, midnight ๐Ÿ”„ Last Modified: April 13, 2026, 6:03 a.m.

7.5

CVSS3.1

CVE-2026-23538 - feast: Resource exhaustion via WebSocket endpoint

A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resourcesโ€”such as memory, CPUโ€ฆ

๐Ÿ“… Published: March 20, 2026, midnight ๐Ÿ”„ Last Modified: March 24, 2026, 10:35 a.m.

5.3

CVSS3.1

CVE-2025-46598 -

Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.

๐Ÿ“… Published: March 20, 2026, midnight ๐Ÿ”„ Last Modified: April 2, 2026, 8:23 p.m.

7.8

CVSS3.1

CVE-2026-23272 - netfilter: nf_tables: unconditionally bump set->nelems before insertion

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nelems before insertion In case that the set is full, a new element gets published then removed without waiting for the RCU grace period, while RCU reader can be walking over it alrโ€ฆ

๐Ÿ“… Published: March 20, 2026, midnight ๐Ÿ”„ Last Modified: April 13, 2026, 6:03 a.m.

8.8

CVSS3.1

CVE-2025-67260 -

The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack Tpโ€ฆ

๐Ÿ“… Published: March 20, 2026, midnight ๐Ÿ”„ Last Modified: April 14, 2026, 8:54 p.m.

5.9

CVSS3.1

CVE-2026-22737 - Spring Framework Improper Path Limitation with Script View Templates

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views.ย This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0โ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:53 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 2:20 p.m.

6.5

CVSS3.1

CVE-2026-32761 - File Browser has an Authorization Policy Bypass in its Public Share Download Flow

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download privileges (perm.download = false) but granted share โ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:10 p.m.

10

CVSS4.0

CVE-2026-32760 - File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-registration (signup = true) is enabled and the defaโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:39 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:42 p.m.

2.6

CVSS3.1

CVE-2026-22735 - Server Sent Event stream corruption

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE).ย This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

๐Ÿ“… Published: March 19, 2026, 11:37 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 2:21 p.m.

5.3

CVSS4.0

CVE-2026-32759 - File Browser TUS Negative Upload-Length Fires Post-Upload Hooks Prematurely

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, the TUS resumable upload handler parses the Upload-Length header as a signed 64-bit integer without validating that the value is nonโ€ฆ

๐Ÿ“… Published: March 19, 2026, 11:31 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 2:10 p.m.
Total resulsts: 349182
Page 1032 of 34,919
ยซ previous page ยป next page
Filters