8.8

CVSS3.1

CVE-2026-3923 - chromium-browser: Use after free in WebMIDI

Use after free in WebMIDI in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 a.m.

7.5

CVSS3.1

CVE-2025-70246 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: March 11, 2026, 4:32 p.m.

9.8

CVSS3.1

CVE-2026-23240 - tls: Fix race condition in tls_sw_cancel_work_tx()

In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), tx_work_handler() can still be scheduled from paths such as โ€ฆ

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 5 p.m.

7.8

CVSS3.1

CVE-2026-23239 - espintcp: Fix race condition in espintcp_close()

In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths such as the Delayed Aโ€ฆ

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 5 p.m.

9.1

CVSS3.1

CVE-2025-69615 -

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: May 7, 2026, 8:48 p.m.

8.8

CVSS3.1

CVE-2026-3917 - chromium-browser: Use after free in Agents

Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 a.m.

6.5

CVSS3.1

CVE-2026-3939 - chromium-browser: Insufficient policy enforcement in PDF

Insufficient policy enforcement in PDF in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted PDF file. (Chromium security severity: Low)

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 3 a.m.

7.5

CVSS3.1

CVE-2025-56421 -

SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: March 20, 2026, 4:58 p.m.

8.8

CVSS3.1

CVE-2026-3918 - chromium-browser: Use after free in WebMCP

Use after free in WebMCP in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

๐Ÿ“… Published: March 10, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 9:30 a.m.

5.3

CVSS4.0

CVE-2026-30927 - Admidio: Event participation IDOR - non-leaders can register other users for events via user_uuid pโ€ฆ

Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OTHER users by manipulating the user_uuid GET parameter. The condition uses || (OR), meaning if possibโ€ฆ

๐Ÿ“… Published: March 9, 2026, 11:03 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, noon
Total resulsts: 349182
Page 1233 of 34,919
ยซ previous page ยป next page
Filters