8.4

CVSS4.0

CVE-2026-32925 - Stack-Based Buffer Overflow in V‑SFT Leading to Arbitrary Code Execution

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

📅 Published: April 1, 2026, 10:58 p.m. 🔄 Last Modified: April 8, 2026, 7:56 p.m.

6.3

CVSS3.1

CVE-2025-66483 - Multiple vulnerabilities have been addressed in IBM Aspera Shares

IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

📅 Published: April 1, 2026, 10:56 p.m. 🔄 Last Modified: April 7, 2026, 7:56 a.m.

6.5

CVSS3.1

CVE-2025-36375 - IBM DataPower Gateway vulnerable to CSRF

IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau…

📅 Published: April 1, 2026, 10:50 p.m. 🔄 Last Modified: April 7, 2026, 7:56 a.m.

5.3

CVSS4.0

CVE-2026-5314 - Nothings stb TTF File stb_truetype.h stbtt_InitFont_internal out-of-bounds

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made p…

📅 Published: April 1, 2026, 10:15 p.m. 🔄 Last Modified: April 1, 2026, 11:17 p.m.

8.8

CVSS3.1

CVE-2026-34572 - CI4MS: Account Deactivation Module Full Persistent Unauthorized Access for All‑Roles via Improper S…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backen…

📅 Published: April 1, 2026, 9:35 p.m. 🔄 Last Modified: April 7, 2026, 7:56 a.m.

8.6

CVSS4.0

CVE-2026-3987 - WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.This issue affects Fireware OS 12.6.1 up to and including 12.11.8 and 2025.1 up to and i…

📅 Published: April 1, 2026, 9:32 p.m. 🔄 Last Modified: April 3, 2026, 4:10 p.m.

10

CVSS3.1

CVE-2026-34571 - CI4MS: Stored Cross‑Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fail…

📅 Published: April 1, 2026, 9:32 p.m. 🔄 Last Modified: April 7, 2026, 7:56 a.m.

8.8

CVSS3.1

CVE-2026-34570 - CI4MS: Account Deletion Module Full Persistent Unauthorized Access for All‑Roles via Improper Sessi…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend de…

📅 Published: April 1, 2026, 9:30 p.m. 🔄 Last Modified: April 7, 2026, 7:56 a.m.

5.3

CVSS4.0

CVE-2026-5313 - Nothings stb GIF Decoder stb_image.h stbi__gif_load_next denial of service

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and…

📅 Published: April 1, 2026, 9:30 p.m. 🔄 Last Modified: April 3, 2026, 4:42 p.m.

10

CVSS3.1

CVE-2026-34569 - CI4MS: Blogs Categories Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM X…

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject …

📅 Published: April 1, 2026, 9:29 p.m. 🔄 Last Modified: April 7, 2026, 7:56 a.m.
Total resulsts: 343974
Page 227 of 34,398
« previous page » next page
Filters