7.5

CVSS3.1

CVE-2026-33282 - Ella Core panics on malformed NGAP Location Report

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` IE. An attacker able to send crafted NGAP messageโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:47 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:27 p.m.

6.5

CVSS3.1

CVE-2026-33281 - Ella Core panics on invalid PDU Session IDs in NGAP messages

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with invalid PDU Session IDs outside of 1-15. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribersโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:46 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:27 p.m.

7.1

CVSS3.1

CVE-2026-33252 - MCP Go SDK Allows Cross-Site Tool Execution for HTTP Servers without Authorizatrion

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Authorization, โ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 4:33 p.m.

8.7

CVSS4.0

CVE-2026-33241 - Salvo Affected by Denial of Service via Unbounded Memory Allocation in Form Data Parsing

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending extโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:41 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-33242 - Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraints and access unintended backend paths (e.g., protโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:40 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:35 p.m.

6.9

CVSS4.0

CVE-2026-4615 - SourceCodester Online Catering Reservation search.php sql injection

A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the file /search.php. Such manipulation of the argument rcode leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

๐Ÿ“… Published: March 23, 2026, 11:38 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.3

CVSS4.0

CVE-2026-4614 - itsourcecode sanitize or validate this input Parameter subjects.php sql injection

A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carrieโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:38 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

7.5

CVSS3.1

CVE-2026-33250 - Crash when receiving specially-crafted packets

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public server. A malicious server can use this to crash the game on the player's โ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:38 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 3:47 p.m.

6.6

CVSS4.0

CVE-2026-33202 - Rails Active Storage has possible glob injection in its DiskService

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlledโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:34 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:35 p.m.

8

CVSS4.0

CVE-2026-33195 - Rails Active Storage has possible Path Traversal in DiskService

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path trโ€ฆ

๐Ÿ“… Published: March 23, 2026, 11:31 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:35 p.m.
Total resulsts: 349182
Page 958 of 34,919
ยซ previous page ยป next page
Filters