6.2

CVSS3.1

CVE-2026-29628 - Stack Overflow in tinyobjloader Causing DoS via Crafted MTL File

A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause a Denial of Service (DoS) via supplying a crafted .mtl file.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:34 p.m.

8

CVSS3.1

CVE-2026-31281 -

Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the application, resulting in executing the code and may lead to session hijacking and executing commands on the victim's browser. NOTE: The supplie…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 24, 2026, 4:34 p.m.

7.3

CVSS3.1

CVE-2026-36948 -

Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.

7.5

CVSS3.1

CVE-2026-30997 - FFmpeg: FFmpeg: Denial of Service via out-of-bounds read

An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 8:12 p.m.

7.5

CVSS3.1

CVE-2025-66769 - Null Pointer Dereference in Nitro PDF Pro Leads to DoS via XFA Packet

A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 4:51 p.m.

2.7

CVSS3.1

CVE-2026-36950 -

Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 3:28 p.m.

5

CVSS3.1

CVE-2026-6845 - Binutils: binutils: denial of service via crafted elf file

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the syst…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 2:48 p.m.

2.7

CVSS3.1

CVE-2026-36874 - SQL Injection in Basic Library System Load Student Script

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 3:45 p.m.

2.7

CVSS3.1

CVE-2026-36920 - SQL Injection Vulnerability in Sourcecodester Online Reviewer System

Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

4.7

CVSS3.1

CVE-2026-31422 - net/sched: cls_flow: fix NULL pointer dereference on shared blocks

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference on shared blocks flow_change() calls tcf_block_q() and dereferences q->handle to derive a default baseclass. Shared blocks leave block->q NULL, causing a NULL deref when a flow f…

πŸ“… Published: April 13, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 9:16 a.m.
Total resulsts: 349182
Page 514 of 34,919
Β« previous page Β» next page
Filters