5.3

CVSS4.0

CVE-2026-5319 - itsourcecode Payroll Management System navbar.php cross site scripting

A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed…

πŸ“… Published: April 2, 2026, 2:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-5318 - LibRaw JPEG DHT losslessjpeg.cpp initval out-of-bounds write

A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. This manipulation of the argument bits[] causes out-of-bounds write. It is possible to initiate the attack remotely. T…

πŸ“… Published: April 2, 2026, 1:45 a.m. πŸ”„ Last Modified: April 7, 2026, 12:16 p.m.

5.3

CVSS4.0

CVE-2026-5317 - Nothings stb stb_vorbis.c start_decoder out-of-bounds write

A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The ve…

πŸ“… Published: April 2, 2026, 12:45 a.m. πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.4

CVSS3.1

CVE-2026-1243 - IBM Content Navigator is affected by , a Cross-Site Scripting (XSS) vulnerability

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

πŸ“… Published: April 2, 2026, 12:14 a.m. πŸ”„ Last Modified: April 8, 2026, 7:56 p.m.

5.3

CVSS4.0

CVE-2026-5316 - Nothings stb stb_vorbis.c setup_free allocation of resources

A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor …

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.0

CVSS3.1

CVE-2026-23414 - tls: Purge async_hold in tls_decrypt_async_wait()

In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wait() returns, every AEAD operation has completed a…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 11, 2026, 1:16 p.m.

9.8

CVSS3.1

CVE-2026-34877 -

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused …

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 7, 2026, 7:56 a.m.

6.1

CVSS3.1

CVE-2026-30252 - Reflected Cross‑Site Scripting in Interzen ZenShare Suite 17.0 Login Endpoint

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

5.5

CVSS3.1

CVE-2026-23412 - netfilter: bpf: defer hook memory release until rcu readers are done

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping hooks via nfnetlink_hooks: BUG: KASAN: slab-use-after-free in nfnl_hook_dump_one.isra.0+0xe71/0x10f0…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:06 a.m.

5.5

CVSS3.1

CVE-2026-23417 - bpf: Fix constant blinding for PROBE_MEM32 stores

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores are not handled by bpf_jit_blind_insn(), allowing user-controlled 32-bit immediates to survive unblinded into JIT-compiled native code wh…

πŸ“… Published: April 2, 2026, midnight πŸ”„ Last Modified: April 13, 2026, 6:07 a.m.
Total resulsts: 344154
Page 242 of 34,416
Β« previous page Β» next page
Filters