8.7

CVSS4.0

CVE-2026-32981 - Ray Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside th…

πŸ“… Published: March 17, 2026, 7:33 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

5.5

CVSS3.1

CVE-2026-3563 - Authenticated Route Override in Devolutions PowerShell Universal

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or Endpoints to override existing application or system routes, resulting in unintended request routing and denial of serv…

πŸ“… Published: March 17, 2026, 7:15 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

8.3

CVSS3.1

CVE-2026-4064 - Missing Authorization Checks in Devolutions PowerShell Universal gRPC Endpoints

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations β€” including reading sensitive data, creating or deleting resources, and di…

πŸ“… Published: March 17, 2026, 7:14 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

8.5

CVSS4.0

CVE-2026-4295 - Arbitrary code execution via crafted project files in Kiro IDE

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. …

πŸ“… Published: March 17, 2026, 7:11 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

6.9

CVSS4.0

CVE-2026-32836 - mackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing

dr_libsΒ dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Atta…

πŸ“… Published: March 17, 2026, 7:10 p.m. πŸ”„ Last Modified: April 27, 2026, 3:19 p.m.

5.1

CVSS4.0

CVE-2026-32837 - mackron / miniaudio Out-of-Bounds Read in BEXT Coding History Parsing

miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination han…

πŸ“… Published: March 17, 2026, 7:10 p.m. πŸ”„ Last Modified: April 27, 2026, 3:38 p.m.

6.1

CVSS4.0

CVE-2026-4358 - Memory safety issues in slot-based execution hash table spill

A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to disk.

πŸ“… Published: March 17, 2026, 7 p.m. πŸ”„ Last Modified: April 2, 2026, 8:23 p.m.

6.8

CVSS4.0

CVE-2025-15584 - Endpoint DLP Driver Filter Communication Port Integer Overflow

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an integer overflow within the filter communication port, leading to a Blue-Screen-of-Death (BS…

πŸ“… Published: March 17, 2026, 6:55 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

7.8

CVSS3.1

CVE-2025-66342 - Memory Corruption via Type Confusion in Canva Affinity EMF Processor Leading to Arbitrary Code Exec…

A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution.

πŸ“… Published: March 17, 2026, 6:52 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.

6.1

CVSS3.1

CVE-2025-62500 - Out-of-Bounds Read in Canva Affinity EMF Handling

An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.

πŸ“… Published: March 17, 2026, 6:52 p.m. πŸ”„ Last Modified: March 24, 2026, 10:54 a.m.
Total resulsts: 349182
Page 1082 of 34,919
Β« previous page Β» next page
Filters