5.3

CVSS3.1

CVE-2026-32630 - file-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry

file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for strea…

πŸ“… Published: March 13, 2026, 8:54 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

7.7

CVSS4.0

CVE-2026-32628 - AnythingLLM has SQL Injection in Built-in SQL Agent Plugin via Unsanitized table_name Parameter

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any user who can invoke the agent to execute arbitrary SQL commands on connected d…

πŸ“… Published: March 13, 2026, 8:50 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

8.7

CVSS3.1

CVE-2026-32627 - cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostname verification silently disabled on the new conne…

πŸ“… Published: March 13, 2026, 8:48 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

9.8

CVSS3.0

CVE-2025-15060 - claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability

claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of claude-hovercraft. Authentication is not required to exploit this vulnerability. The specific flaw exists wit…

πŸ“… Published: March 13, 2026, 8:43 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

6.3

CVSS3.0

CVE-2026-2491 - Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability

Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Socomec DIRIS A-40 power monitoring devices. Authentication is not required to exploit this vulnerability. The specific flaw e…

πŸ“… Published: March 13, 2026, 8:43 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

7.5

CVSS3.0

CVE-2026-2493 - IceWarp collaboration Directory Traversal Information Disclosure Vulnerability

IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw exists within handling …

πŸ“… Published: March 13, 2026, 8:42 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

7.8

CVSS3.1

CVE-2026-3084 - GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability

GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depend…

πŸ“… Published: March 13, 2026, 8:42 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

7.8

CVSS3.1

CVE-2026-2921 - GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability

GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on …

πŸ“… Published: March 13, 2026, 8:41 p.m. πŸ”„ Last Modified: March 29, 2026, 1:16 p.m.

8.8

CVSS3.1

CVE-2026-3083 - GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending …

πŸ“… Published: March 13, 2026, 8:41 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.

7.8

CVSS3.1

CVE-2026-3086 - GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability

GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depe…

πŸ“… Published: March 13, 2026, 8:40 p.m. πŸ”„ Last Modified: March 23, 2026, 1:39 p.m.
Total resulsts: 349182
Page 1119 of 34,919
Β« previous page Β» next page
Filters