8.8

CVSS4.0

CVE-2026-31963 - HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses reference-based compression so that instead of storing the full sequence for each alignment record it st…

πŸ“… Published: March 18, 2026, 6:22 p.m. πŸ”„ Last Modified: March 25, 2026, 11:52 a.m.

0.0

CVE-2026-4402 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: March 18, 2026, 6:15 p.m. πŸ”„ Last Modified: April 8, 2026, 12:35 p.m.

0

CVSS4.0

CVE-2026-3479 - pkgutil.get_data() does not enforce documented restrictions

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_dat…

πŸ“… Published: March 18, 2026, 6:13 p.m. πŸ”„ Last Modified: April 8, 2026, 8:01 p.m.

8.8

CVSS4.0

CVE-2026-31962 - HTSlib CRAM reader has heap buffer overflow due to improper validation of input

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and quality values, the format also allows them to omit this data in certain cases to save space. Due to som…

πŸ“… Published: March 18, 2026, 6:08 p.m. πŸ”„ Last Modified: March 25, 2026, 11:52 a.m.

7.5

CVSS3.1

CVE-2026-27135 - nghttp2 Denial of service: Assertion failure due to the missing state validation

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They mig…

πŸ“… Published: March 18, 2026, 5:59 p.m. πŸ”„ Last Modified: March 24, 2026, 10:58 a.m.

8.1

CVSS3.1

CVE-2026-32634 - Glances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later builds connection URIs from the untrusted advertised name instead of…

πŸ“… Published: March 18, 2026, 5:55 p.m. πŸ”„ Last Modified: March 24, 2026, 10:58 a.m.

9.1

CVSS3.1

CVE-2026-32633 - Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList.get_servers_list()`. Those objects are mutated in-place during background polling and can contain a…

πŸ“… Published: March 18, 2026, 5:53 p.m. πŸ”„ Last Modified: March 24, 2026, 10:58 a.m.

5.9

CVSS3.1

CVE-2026-32632 - Glances's REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding

Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the MCP endpoint, but prior to version 4.5.2, the main REST/WebUI FastAPI application still accepts arbitrary `Host` headers and does not apply `TrustedHostMiddleware` or an equivale…

πŸ“… Published: March 18, 2026, 5:47 p.m. πŸ”„ Last Modified: March 24, 2026, 10:58 a.m.

4.9

CVSS3.1

CVE-2026-26948 - Exposure of Sensitive System Information Due to Uncleared Debug Information in Dell iDRAC9 and iDRA…

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit…

πŸ“… Published: March 18, 2026, 5:40 p.m. πŸ”„ Last Modified: March 24, 2026, 10:58 a.m.

5.3

CVSS3.1

CVE-2026-26945 - Process Control Vulnerability in Dell Integrated Dell Remote Access Controller (iDRAC)

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent net…

πŸ“… Published: March 18, 2026, 5:27 p.m. πŸ”„ Last Modified: March 24, 2026, 10:58 a.m.
Total resulsts: 349182
Page 1061 of 34,919
Β« previous page Β» next page
Filters