5.5

CVSS3.1

CVE-2026-3836 - dnf5: dnf5: Denial of Service via path traversal in D-Bus locale configuration

A flaw was found in dnf5. A local, unprivileged attacker can exploit a path traversal vulnerability in the D-Bus locale configuration. By providing a specially crafted string to the locale key during session opening, the attacker can force the dnf5daemon-server to terminate, leading to an applicati…

📅 Published: March 9, 2026, 12:34 p.m. 🔄 Last Modified: March 25, 2026, 11:49 a.m.

5.1

CVSS4.0

CVE-2026-3819 - SourceCodester Resort Reservation System Reservation Management page cross site scripting

A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown function of the file /?page=manage_reservation of the component Reservation Management Module. Such manipulation of the argument ID leads to cross site scripting. The attack may be lau…

📅 Published: March 9, 2026, 12:32 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

7.5

CVSS3.1

CVE-2026-3038 - Local DoS and possible privilege escalation via routing sockets

The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on the stack. It assumes that the source sockaddr length field had already been validated, but this is not necessarily the case, and it…

📅 Published: March 9, 2026, 12:25 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

4.4

CVSS3.1

CVE-2026-21736 - GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.

📅 Published: March 9, 2026, 12:23 p.m. 🔄 Last Modified: April 16, 2026, 10:15 a.m.

7.5

CVSS3.1

CVE-2026-2261 - blocklistd(8) socket leak

Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a certain number of leaked sockets is reached, blocklistd becomes unable to run the helper script: a child process is forked, but this child dereferences a null pointer and crashes befo…

📅 Published: March 9, 2026, 12:10 p.m. 🔄 Last Modified: April 16, 2026, 4:15 a.m.

6.9

CVSS4.0

CVE-2026-3818 - Tiandy Easy7 CMS Windows GetDBData.jsp sql injection

A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This manipulation of the argument strTBName causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. The ven…

📅 Published: March 9, 2026, 12:02 p.m. 🔄 Last Modified: April 17, 2026, noon

7.5

CVSS3.1

CVE-2025-15576 - Jail chroot escape via fd exchange with a different jail

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has configured one. In this ca…

📅 Published: March 9, 2026, 11:54 a.m. 🔄 Last Modified: March 17, 2026, 3:54 p.m.

8.8

CVSS3.1

CVE-2025-15547 - Jail escape by a privileged user via nullfs

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks. If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup log…

📅 Published: March 9, 2026, 11:46 a.m. 🔄 Last Modified: March 17, 2026, 3:55 p.m.

7.5

CVSS3.1

CVE-2025-14769 - ipfw denial of service

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference. Maliciously crafted packets sent from a remote host …

📅 Published: March 9, 2026, 11:34 a.m. 🔄 Last Modified: March 17, 2026, 3:55 p.m.

6.9

CVSS4.0

CVE-2026-3817 - SourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorizat…

A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is now public and may be…

📅 Published: March 9, 2026, 11:32 a.m. 🔄 Last Modified: April 16, 2026, 10:30 a.m.
Total resulsts: 349182
Page 1240 of 34,919
« previous page » next page
Filters