4.8

CVSS4.0

CVE-2026-1998 - micropython runtime.c mp_import_all memory corruption

A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 570744d06c5ba9dba59b4c3โ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 6:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:45 p.m.

4.8

CVSS4.0

CVE-2026-1991 - libuvc UVC Descriptor device.c uvc_scan_streaming null pointer dereference

A vulnerability was detected in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit is now public and may be useโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 5:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 p.m.

4.8

CVSS4.0

CVE-2026-1990 - oatpp Type.hpp ObjectWrapper null pointer dereference

A security vulnerability has been detected in oatpp up to 1.3.1. This impacts the function oatpp::data::type::ObjectWrapper::ObjectWrapper of the file src/oatpp/data/type/Type.hpp. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has โ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 5:02 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11 p.m.

4.8

CVSS4.0

CVE-2026-1979 - mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free

A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This paโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 4:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:45 p.m.

6.9

CVSS4.0

CVE-2026-1978 - kalyan02 NanoCMS User Information pagesdata.txt direct request

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploiโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 4:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:45 p.m.

5.3

CVSS4.0

CVE-2026-1977 - isaacwasserman mcp-vegalite-server visualize_data eval code injection

A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. Theโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 3:32 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11 p.m.

8.8

CVSS3.1

CVE-2025-15566 - ingress-nginx auth-proxy-set-headers nginx configuration injection

A security issue was discovered in ingress-nginxย where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets acceโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 3:13 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

6.9

CVSS4.0

CVE-2026-1976 - Free5GC SMF SessionDeletionResponse null pointer dereference

A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used forโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 3:02 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11 p.m.

6.9

CVSS4.0

CVE-2026-1975 - Free5GC pfcp_reports.go identityTriggerType null pointer dereference

A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. โ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 2:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 p.m.

4.3

CVSS3.1

CVE-2026-1228 - Timeline Block <= 1.3.3 - Insecure Direct Object Reference to Authenticated (Author+) Private Timelโ€ฆ

The Timeline Block โ€“ Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.3 via the tlgb_shortcode() function due to missing validation on a user controlled key. Thโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 2:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:24 p.m.
Total resulsts: 349182
Page 1779 of 34,919
ยซ previous page ยป next page
Filters