6.4

CVSS3.1

CVE-2026-24309 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module to read, modify or insert entries into the database configuration table of the ABAP system. This unauthorized content change could lead to reduced s…

πŸ“… Published: March 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 16, 2026, 10 a.m.

6.1

CVSS3.1

CVE-2026-0489 - DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)

Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue ha…

πŸ“… Published: March 10, 2026, 12:17 a.m. πŸ”„ Last Modified: April 17, 2026, noon

4.3

CVSS3.1

CVE-2026-3927 - chromium-browser: Incorrect security UI in PictureInPicture

Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 9:30 a.m.

6.5

CVSS3.1

CVE-2026-3930 - chromium-browser: Unsafe navigation in Navigation

Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 3 a.m.

9.4

CVSS3.1

CVE-2025-69614 -

Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: May 7, 2026, 8:50 p.m.

6.1

CVSS3.1

CVE-2025-70128 -

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using…

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 1:21 a.m.

7.5

CVSS3.1

CVE-2025-70249 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizard2.

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: March 11, 2026, 4:30 p.m.

8.8

CVSS3.1

CVE-2026-3914 - chromium-browser: Integer overflow in WebML

Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 9:30 a.m.

4.3

CVSS3.1

CVE-2026-3940 - chromium-browser: Insufficient policy enforcement in DevTools

Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 9:30 a.m.

7.5

CVSS3.1

CVE-2025-70251 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formWlanGuestSetup.

πŸ“… Published: March 10, 2026, midnight πŸ”„ Last Modified: March 11, 2026, 4:28 p.m.
Total resulsts: 349182
Page 1229 of 34,919
Β« previous page Β» next page
Filters