2.3

CVSS4.0

CVE-2026-3465 - Tuya App/SDK JSON Data Point denial of service

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The com…

πŸ“… Published: March 3, 2026, 3:02 p.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

8.4

CVSS4.0

CVE-2026-28518 - OpenViking .ovpack Import ZIP Slip Path Traversal

OpenViking versions 0.2.1 and prior, fixed in commitΒ 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attackers to write files outside the intended import directory. Attackers can craft malicious ZIP archives with traversal sequences, absolute paths, or dri…

πŸ“… Published: March 3, 2026, 2:36 p.m. πŸ”„ Last Modified: April 17, 2026, 9:19 p.m.

6.1

CVSS3.1

CVE-2025-64736 -

An out-of-bounds read vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (5462afb0). A specially crafted .abf file can lead to an information leak. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“… Published: March 3, 2026, 2:32 p.m. πŸ”„ Last Modified: March 5, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2026-22891 - Heap Overflow in libbiosig Intan CLP Parsing Leading to Arbitrary Code Execution

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerabilit…

πŸ“… Published: March 3, 2026, 2:32 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 p.m.

8.1

CVSS3.1

CVE-2026-20777 - Heap Overflow in Biosig libbiosig 3.9.2 Enables Code Execution

A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

πŸ“… Published: March 3, 2026, 2:32 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.

3.7

CVSS3.1

CVE-2026-25674 - Potential incorrect permissions on newly created file system objects

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread's t…

πŸ“… Published: March 3, 2026, 2:28 p.m. πŸ”„ Last Modified: April 17, 2026, 1:30 p.m.

7.5

CVSS3.1

CVE-2026-25673 - Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit()`, which performs NFKC normalization on Windows that is disproportionately slow for certain Unicode characters, allowing a remote attacker to cause d…

πŸ“… Published: March 3, 2026, 2:28 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 p.m.

8.5

CVSS4.0

CVE-2026-2637 -

iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd.Β The daemon exposes an NSConnection service that runs as root without implementing any authentication or authorization checks. This issue affects iBoysoft NTFS: 8.0.0.

πŸ“… Published: March 3, 2026, 2:04 p.m. πŸ”„ Last Modified: April 27, 2026, 1:12 p.m.

6.9

CVSS4.0

CVE-2026-3344 - WatchGuard Firebox System Integrity Check Bypass

A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: April 16, 2026, 2:15 p.m.

5.1

CVSS4.0

CVE-2026-3343 - WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. This vulnerability affects Fireware OS 12.7 up to and including 12.11.7…

πŸ“… Published: March 3, 2026, 1:17 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.
Total resulsts: 348441
Page 1288 of 34,845
Β« previous page Β» next page
Filters