9.4

CVSS4.0

CVE-2026-33026 - nginx-ui Backup Restore Allows Tampering with Encrypted Backups

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

๐Ÿ“… Published: March 30, 2026, 7:26 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:53 a.m.

5.3

CVSS3.1

CVE-2026-21714 - Node.js: Node.js: Memory leak and Denial of Service via crafted HTTP/2 WINDOW_UPDATE frames

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2ยณยน-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulneraโ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:54 a.m.

5.9

CVSS3.1

CVE-2026-21717 - nodejs: v8: Node.js: Denial of Service via V8 string hashing mechanism due to predictable hash collโ€ฆ

A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.โ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:38 a.m.

5.2

CVSS3.1

CVE-2026-21711 - Node.js: Node.js: Unauthorized inter-process communication due to missing Unix Domain Socket permisโ€ฆ

A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose lโ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:54 a.m.

3.8

CVSS3.1

CVE-2026-21716 - nodejs: Node.js: Permission bypass allows unauthorized modification of file permissions and ownershโ€ฆ

An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with โ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:54 a.m.

5.9

CVSS3.1

CVE-2026-21713 - Node.js: Node.js: Information disclosure via timing oracle in HMAC verification

A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior coโ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:38 a.m.

7.5

CVSS3.1

CVE-2026-21710 - Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` toโ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 7:54 a.m.

3.3

CVSS3.1

CVE-2026-21715 - Node.js: Node.js: Information disclosure due to `fs.realpathSync.native()` bypassing filesystem reaโ€ฆ

A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still usโ€ฆ

๐Ÿ“… Published: March 30, 2026, 7:07 p.m. ๐Ÿ”„ Last Modified: April 3, 2026, 9:38 a.m.

6.9

CVSS4.0

CVE-2026-5147 - YunaiV yudao-cloud get-by-website sql injection

A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-website. The manipulation of the argument Website results in sql injection. It is possible to launch the attack remotely. The exploit has been released tโ€ฆ

๐Ÿ“… Published: March 30, 2026, 6:45 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:24 p.m.

9.2

CVSS3.1

CVE-2026-34714 - vim: Vim: Arbitrary code execution via crafted file

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

๐Ÿ“… Published: March 30, 2026, 6:27 p.m. ๐Ÿ”„ Last Modified: April 3, 2026, 12:16 p.m.
Total resulsts: 343040
Page 187 of 34,304
ยซ previous page ยป next page
Filters