6.5

CVSS3.1

CVE-2026-33033 - Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such a…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.

2.7

CVSS3.1

CVE-2026-4292 - Privilege abuse in ModelAdmin.list_editable

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evalu…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 13, 2026, 5:34 p.m.

9.8

CVSS3.1

CVE-2026-4277 - Privilege abuse in GenericInlineModelAdmin

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evalua…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.

8.2

CVSS3.1

CVE-2026-35457 - libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in …

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 24, 2026, 1:32 p.m.

7.5

CVSS3.1

CVE-2026-3902 - ASGI header spoofing via underscore/hyphen conflation

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Djan…

πŸ“… Published: April 7, 2026, 2:22 p.m. πŸ”„ Last Modified: April 14, 2026, 4:40 p.m.

7.5

CVSS3.1

CVE-2026-35405 - libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A malicious peer can just keep registering unique namespaces in a loop and the server happily accepts e…

πŸ“… Published: April 7, 2026, 2:21 p.m. πŸ”„ Last Modified: April 24, 2026, 1:37 p.m.

5.8

CVSS3.1

CVE-2026-5384 - runZero Platform incorrect credential scope

An issue that could allow a credential to be updated and used for a task from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N (5.8 Medium). This i…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 21, 2026, 3:40 p.m.

4.4

CVSS3.1

CVE-2026-5383 - runZero Explorer missing authorization check

An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L (4.4 Medium). This issue was fixed in ver…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 21, 2026, 3:39 p.m.

3

CVSS3.1

CVE-2026-5382 - runZero Platform MCP endpoint information leak

An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N (3.0 Low). This issue was fixed in v…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 21, 2026, 3:37 p.m.

2.2

CVSS3.1

CVE-2026-5381 - runZero Platform task information leak

An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N (2.2 Low). This issue was fixed in version 4.0.260205.…

πŸ“… Published: April 7, 2026, 2:12 p.m. πŸ”„ Last Modified: April 21, 2026, 3:36 p.m.
Total resulsts: 349182
Page 637 of 34,919
Β« previous page Β» next page
Filters