9.8

CVSS3.1

CVE-2026-34877 -

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused …

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

6.1

CVSS3.1

CVE-2026-30252 -

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 10, 2026, 3:50 p.m.

0.0

CVE-2026-23416 - mm/mseal: update VMA end correctly on merge

In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previously we stored the end of the current VMA in curr_end, and then upon iterating to the next VMA updated curr_start to curr_end to advance to the next VMA. However, this doesn't ta…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

5.5

CVSS3.1

CVE-2026-23415 - futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy()

In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During futex_key_to_node_opt() execution, vma->vm_policy is read under speculative mmap lock and RCU. Concurrently, mbind() may call vma_replace_policy() whi…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.5

CVSS3.1

CVE-2026-23412 - netfilter: bpf: defer hook memory release until rcu readers are done

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks: BUG: KASAN: slab-use-after-free in nfnl_hook_dump_one.isra.0+0xe71/0x10f0…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

6.1

CVSS3.1

CVE-2026-30251 -

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 9, 2026, 1:10 a.m.

7.5

CVSS3.1

CVE-2026-34876 -

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation o…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:56 p.m.

5.3

CVSS3.1

CVE-2026-26895 -

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 7:56 p.m.

5.5

CVSS3.1

CVE-2026-23413 - clsact: Fix use-after-free in init/destroy rollback asymmetry

In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback asymmetry Fix a use-after-free in the clsact qdisc upon init/destroy rollback asymmetry. The latter is achieved by first fully initializing a clsact instance, and then in a seco…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 9:17 p.m.

7.0

CVSS3.1

CVE-2026-23414 - tls: Purge async_hold in tls_decrypt_async_wait()

In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wait() returns, every AEAD operation has completed a…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 11, 2026, 1:16 p.m.
Total resulsts: 343968
Page 224 of 34,397
Β« previous page Β» next page
Filters