7.2

CVSS4.0

CVE-2026-2273 - Code Injection via Malicious Project Files in Schneider Electric EcoStruxure Automation Expert

CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of โ€ฆ

๐Ÿ“… Published: March 10, 2026, 5:18 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:45 a.m.

5.4

CVSS3.1

CVE-2026-30964 - Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exactโ€ฆ

web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. Prior to 5.2.4, when allowed_origins is configured, CheckAllowedOrigins reduces URL-like values to their host component and aโ€ฆ

๐Ÿ“… Published: March 10, 2026, 5:16 p.m. ๐Ÿ”„ Last Modified: May 7, 2026, 6:35 p.m.

9.4

CVSS4.0

CVE-2026-30960 - RSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI Interface

rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics simulations functionalities. The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Functโ€ฆ

๐Ÿ“… Published: March 10, 2026, 5:11 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:45 a.m.

7

CVSS4.0

CVE-2026-1286 - Deserialization Vulnerability in EcoStruxure Foxboro DCS Allows Remote Code Execution

CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.

๐Ÿ“… Published: March 10, 2026, 5:09 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:45 a.m.

5.3

CVSS4.0

CVE-2026-30959 - OneUptime has WhatsApp Resend Verification Authorization Bypass

OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects the UserWhatsAppAPIโ€ฆ

๐Ÿ“… Published: March 10, 2026, 5:06 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:45 a.m.

5.1

CVSS4.0

CVE-2025-13902 -

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victimโ€™s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server coโ€ฆ

๐Ÿ“… Published: March 10, 2026, 5:06 p.m. ๐Ÿ”„ Last Modified: March 11, 2026, 1:53 p.m.

7.5

CVSS3.1

CVE-2026-26144 - Microsoft Excel Information Disclosure Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

๐Ÿ“… Published: March 10, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:36 p.m.

7.8

CVSS3.1

CVE-2026-26141 - Hybrid Worker Extension (Arcโ€‘enabled Windows VMs) Elevation of Privilege Vulnerability

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

๐Ÿ“… Published: March 10, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:36 p.m.

7.5

CVSS3.1

CVE-2026-26130 - ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

๐Ÿ“… Published: March 10, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 11:45 p.m.

8.8

CVSS3.1

CVE-2026-26118 - Azure MCP Server Tools Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

๐Ÿ“… Published: March 10, 2026, 5:05 p.m. ๐Ÿ”„ Last Modified: April 14, 2026, 4:36 p.m.
Total resulsts: 349182
Page 1212 of 34,919
ยซ previous page ยป next page
Filters