8

CVSS3.1

CVE-2026-43003 -

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.

πŸ“… Published: May 1, 2026, midnight πŸ”„ Last Modified: May 1, 2026, 8:07 a.m.

8.7

CVSS4.0

CVE-2026-7513 - UTT HiPER 1200GW formRemoteControl strcpy buffer overflow

A vulnerability has been found in UTT HiPER 1200GW up to 2.5.3-170306. The impacted element is the function strcpy of the file /goform/formRemoteControl. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: April 30, 2026, 11:45 p.m. πŸ”„ Last Modified: April 30, 2026, 11:45 p.m.

8.7

CVSS4.0

CVE-2026-7512 - UTT HiPER 1200GW formUser strcpy buffer overflow

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-1703. The affected element is the function strcpy of the file /goform/formUser. Executing a manipulation can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: April 30, 2026, 11:30 p.m. πŸ”„ Last Modified: April 30, 2026, 11:30 p.m.

5

CVSS3.1

CVE-2026-22726 - Route Services Firewall Bypass

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachabl…

πŸ“… Published: April 30, 2026, 11:17 p.m. πŸ”„ Last Modified: April 30, 2026, 11:26 p.m.

4.7

CVSS3.1

CVE-2026-5404 - Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark

K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

πŸ“… Published: April 30, 2026, 11:04 p.m. πŸ”„ Last Modified: April 30, 2026, 11:04 p.m.

7.8

CVSS3.1

CVE-2026-5403 - Heap-based Buffer Overflow in Wireshark

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

πŸ“… Published: April 30, 2026, 11:04 p.m. πŸ”„ Last Modified: April 30, 2026, 11:04 p.m.

7

CVSS3.1

CVE-2026-5656 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Wireshark

Profile import path traversal in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

πŸ“… Published: April 30, 2026, 11:03 p.m. πŸ”„ Last Modified: April 30, 2026, 11:03 p.m.

7.8

CVSS3.1

CVE-2026-5405 - Heap-based Buffer Overflow in Wireshark

RDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

πŸ“… Published: April 30, 2026, 11:03 p.m. πŸ”„ Last Modified: April 30, 2026, 11:03 p.m.

5.3

CVSS4.0

CVE-2026-7510 - OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publi…

πŸ“… Published: April 30, 2026, 11 p.m. πŸ”„ Last Modified: April 30, 2026, 11 p.m.

5.3

CVSS4.0

CVE-2026-7508 - Bootstrap CMS Page Creation show.blade.php code injection

A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulation of the argument body results in code injection. Remote exploitation of the attack is possible. T…

πŸ“… Published: April 30, 2026, 10:45 p.m. πŸ”„ Last Modified: April 30, 2026, 10:45 p.m.
Total resulsts: 347405
Page 4 of 34,741
Β« previous page Β» next page
Filters