7.8

CVSS3.1

CVE-2026-24071 - XPC Client Validation via PID leading to Local Privilege Escalation in Native Instruments Native Ac…

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argum…

📅 Published: Feb. 2, 2026, 1:23 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

8.8

CVSS3.1

CVE-2026-24070 - Local Privilege Escalation via DYLIB Injection in Native Instruments Native Access

During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permissions, is deployed as well. The communication with the XPC servi…

📅 Published: Feb. 2, 2026, 1:15 p.m. 🔄 Last Modified: April 29, 2026, 8:33 a.m.

8.6

CVSS3.1

CVE-2025-8587 - Time-Based Blind SQLi in AKCE Software's SKSPro

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows SQL Injection.This issue affects SKSPro: through 07012026.

📅 Published: Feb. 2, 2026, 12:50 p.m. 🔄 Last Modified: March 16, 2026, 6:17 p.m.

5.6

CVSS3.1

CVE-2026-1766 - localsearch: GNOME localsearch MP3 Extractor: Denial of Service and information disclosure via malf…

A flaw was found in GNOME localsearch MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a mali…

📅 Published: Feb. 2, 2026, 11:11 a.m. 🔄 Last Modified: Feb. 2, 2026, 11:11 a.m.

5.6

CVSS3.1

CVE-2026-1764 - localsearch: GNOME localsearch MP3 Extractor: Heap buffer overflow leads to denial of service or in…

A flaw was found in GNOME localsearch MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (Do…

📅 Published: Feb. 2, 2026, 11:11 a.m. 🔄 Last Modified: Feb. 2, 2026, 11:11 a.m.

5.6

CVSS3.1

CVE-2026-1767 - localsearch: GNOME localsearch MP3 Extractor: Heap buffer overflow leading to denial of service or …

A flaw was found in the GNOME localsearch MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer…

📅 Published: Feb. 2, 2026, 11:11 a.m. 🔄 Last Modified: Feb. 2, 2026, 11:11 a.m.

5.6

CVSS3.1

CVE-2026-1765 - localsearch: GNOME localsearch MP3 Extractor: Denial of Service and potential information disclosur…

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch. This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the applic…

📅 Published: Feb. 2, 2026, 11:11 a.m. 🔄 Last Modified: Feb. 2, 2026, 11:11 a.m.

7.5

CVSS3.0

CVE-2026-0599 - Unbounded External Image Fetch in Validation Leads to Resource-Exhaustion DoS in huggingface/text-g…

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET re…

📅 Published: Feb. 2, 2026, 10:36 a.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

9.1

CVSS3.0

CVE-2024-5986 - Remote Arbitrary File Write with Arbitrary Data in h2oai/h2o-3

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the `/3/Frames/framename/…

📅 Published: Feb. 2, 2026, 10:36 a.m. 🔄 Last Modified: April 15, 2026, 2:34 p.m.

5.7

CVSS3.0

CVE-2025-7105 - Denial of Service via JavaScript Memory Overflow in danny-avila/librechat

A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents rapidly. If the forked content includes a Mermaid graph with a large number of nodes, it can lead to a JavaScript heap out of memory error upon service…

📅 Published: Feb. 2, 2026, 10:36 a.m. 🔄 Last Modified: April 15, 2026, 2:34 p.m.
Total resulsts: 349182
Page 1861 of 34,919
« previous page » next page
Filters