CVE zaktualizowane w ostatnich 24 godzinach — 105 wpisów. Mogą zawierać nowe CVSS, EPSS, informacje o patchu lub zmiany statusu KEV.

CVE-2026-31431 🔴 Łataj teraz KEV
os

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is…

7.8 CVSS
2.6% EPSS
linuxexploit 2026-04-22
CVE-2019-25597 ⚪ Do wiadomości

NSauditor 3.1.2.0 contains a buffer overflow vulnerability in the SNMP Auditor Community field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a large pay…

6.2 CVSS
0.0% EPSS
CVE-2020-37130 🟡 Monitoruj

Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated charact…

7.5 CVSS
0.0% EPSS
nsasoftdosexploit 2026-02-05
CVE-2021-47815 🟡 Monitoruj

Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key'…

7.5 CVSS
0.0% EPSS
nsasoftdosexploit 2026-01-16
CVE-2026-2625 ⚪ Do wiadomości
os

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file. During the RPM signature verification process, this crafted file can t…

4.0 CVSS
0.0% EPSS
redhatdos 2026-04-03
CVE-2018-25213 🟠 Łataj w tym tygodniu

Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a p…

8.4 CVSS
0.0% EPSS
CVE-2025-57853 ⚪ Do wiadomości
os

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attack…

6.4 CVSS
0.0% EPSS
CVE-2026-7141 ⚪ Do wiadomości

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block Handler. Performing a manipulation results in unin…

5.6 CVSS
0.1% EPSS
vllm 2026-04-27
CVE-2025-57851 ⚪ Do wiadomości
os

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain…

6.4 CVSS
0.0% EPSS
CVE-2026-7094 🟡 Monitoruj

A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78. Affected by this issue is some unknown functionality of the file src/puppeteer/index.ts of the compone…

7.3 CVSS
0.0% EPSS
CVE-2026-7023 ⚪ Do wiadomości

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component databaseTo…

6.3 CVSS
0.0% EPSS
CVE-2026-7020 ⚪ Do wiadomości

A security flaw has been discovered in Ollama up to 0.20.2. This affects the function digestToPath of the file x/imagegen/transfer/transfer.go of the component Tensor Model Transfer Handler. The manipulation of the argum…

5.6 CVSS
0.0% EPSS
CVE-2026-6987 🟡 Monitoruj

A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injectio…

7.3 CVSS
2.1% EPSS
sipeedexploitrce 2026-04-25
CVE-2026-41360 ⚪ Do wiadomości

OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exec flows. Attackers can replace approved local scripts before execution …

6.7 CVSS
0.0% EPSS
openclaw 2026-04-23
CVE-2026-41358 ⚪ Do wiadomości

OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attackers can inject unauthorized thread messages through allowlisted user repl…

5.4 CVSS
0.0% EPSS
openclaw 2026-04-23
CVE-2026-41355 🟡 Monitoruj

OpenShell before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hooks. Attackers with mirror mode access can execute arbitrary code on the…

7.3 CVSS
0.0% EPSS
openclawrce 2026-04-23
CVE-2025-57847 ⚪ Do wiadomości
os

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certai…

6.4 CVSS
0.0% EPSS
CVE-2026-41354 ⚪ Do wiadomości

OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. Attackers can exploit weak dedupl…

3.7 CVSS
0.1% EPSS
openclaw 2026-04-23
CVE-2026-41353 🟡 Monitoruj

OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile sele…

8.1 CVSS
0.1% EPSS
openclaw 2026-04-23
CVE-2026-34764 ⚪ Do wiadomości

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU…

2.3 CVSS
0.0% EPSS
electronjs 2026-04-06
CVE-2026-34444 🔴 Łataj teraz

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows …

10.0 CVSS
0.0% EPSS
scoderexploitrce 2026-04-06
CVE-2026-5673 ⚪ Do wiadomości
os

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically in the avi_parse_input_file() function. A local attacker could exploit t…

5.6 CVSS
0.0% EPSS
redhatexploit 2026-04-06
CVE-2026-3184 ⚪ Do wiadomości

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could…

3.7 CVSS
0.1% EPSS
kernel 2026-04-03
CVE-2026-5201 🟡 Monitoruj
os

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG imag…

7.5 CVSS
0.2% EPSS
CVE-2026-41414 🟡 Monitoruj

Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it via cargo run, with access to SKIM_RS_BOT…

7.4 CVSS
0.0% EPSS
skim-rsexploit 2026-04-24
CVE-2026-35613 ⚪ Do wiadomości

coursevault-preview is a utility for previewing course material files from a configured directory. coursevault-preview versions prior to 0.1.1 contain a path traversal vulnerability in the resolveSafe utility. The bounda…

5.1 CVSS
0.0% EPSS
CVE-2026-34219 ⚪ Do wiadomości

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. A…

5.9 CVSS
0.1% EPSS
protocolexploit 2026-03-31
CVE-2026-33040 🟡 Monitoruj

libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation accepts attacker-controlled PRUNE backoff values and may perform unchecke…

7.5 CVSS
0.0% EPSS
protocol 2026-03-20
CVE-2026-23500 🔴 Łataj teraz

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF c…

9.1 CVSS
0.1% EPSS
dolibarrexploitrce 2026-04-17
CVE-2026-40491 ⚪ Do wiadomości

gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the …

6.5 CVSS
0.0% EPSS
CVE-2026-3517 🟡 Monitoruj

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by…

8.4 CVSS
0.1% EPSS
progressrce 2026-04-20
CVE-2026-3518 🟡 Monitoruj

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting uns…

8.4 CVSS
0.1% EPSS
progressrce 2026-04-20
CVE-2026-3519 🟡 Monitoruj

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by …

8.4 CVSS
0.1% EPSS
progressrce 2026-04-20
CVE-2026-4800 🟡 Monitoruj

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both path…

8.1 CVSS
0.1% EPSS
lodash 2026-03-31
CVE-2026-7321 🟠 Łataj w tym tygodniu

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

9.6 CVSS
0.0% EPSS
mozilla 2026-04-28
CVE-2026-23865 ⚪ Do wiadomości

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType vari…

5.3 CVSS
0.0% EPSS
freetype 2026-03-02
CVE-2026-4048 🟡 Monitoruj

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsa…

8.4 CVSS
0.1% EPSS
progressrce 2026-04-20
CVE-2026-39911 🟡 Monitoruj

Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to e…

8.8 CVSS
0.1% EPSS
hedera 2026-04-09
CVE-2026-30922 🟡 Monitoruj

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures…

7.5 CVSS
0.0% EPSS
pyasn1dosexploit 2026-03-18
CVE-2026-40542 🟡 Monitoruj
apps

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to u…

7.3 CVSS
0.1% EPSS
apache 2026-04-22
CVE-2025-67030 🟡 Monitoruj

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

8.8 CVSS
0.3% EPSS
CVE-2026-39396 ⚪ Do wiadomości

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decom…

3.1 CVSS
0.0% EPSS
openbaoexploit 2026-04-21
CVE-2026-25542 ⚪ Do wiadomości

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a resource source string (refSource.URI) against spec.resour…

6.5 CVSS
0.0% EPSS
CVE-2026-7040 🟡 Monitoruj

Text::Minify::XS versions from 0.3.0 before 0.7.8 for Perl have a heap overflow when processing some malformed UTF-8 characters. The minify functions mishandled some malformed UTF-8 characters, leading to heap corruptio…

7.5 CVSS
0.0% EPSS
buffer-overflow 2026-04-27
CVE-2026-5088 🟡 Monitoruj

Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to gene…

7.5 CVSS
0.1% EPSS
2026-04-15
CVE-2026-2297 ⚪ Do wiadomości

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this…

0.0 CVSS
0.0% EPSS
2026-03-04
CVE-2025-13462 ⚪ Do wiadomości

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archi…

0.0 CVSS
0.0% EPSS
2026-03-12
CVE-2022-45047 🟠 Łataj w tym tygodniu
apps

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations th…

9.8 CVSS
5.7% EPSS
CVE-2026-40903 🟠 Łataj w tym tygodniu

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present…

9.1 CVSS
0.0% EPSS
goshs 2026-04-21
CVE-2026-41386 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pai…

9.1 CVSS
0.0% EPSS
CVE-2026-41385 ⚪ Do wiadomości

OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attackers can retrieve unredacted configuration data to…

6.5 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41384 🟡 Monitoruj

OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables through workspace configuration. Attackers can …

7.8 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41383 🟡 Monitoruj

OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorkspaceDir and remoteAgentWorkspaceDir configuratio…

8.1 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41382 ⚪ Do wiadomości

OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member allowlist restrictions. Attackers can exploit stale-role validation gap…

5.4 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41381 ⚪ Do wiadomości

OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level member access allowlist restrictions. Attackers can send Discord voice …

5.4 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41380 🟡 Monitoruj

OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables instead of invoked targets. Attackers can ex…

7.3 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41379 🟡 Monitoruj

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Talk Voice configuration persistence. Attackers with operator.write pr…

7.1 CVSS
0.0% EPSS
CVE-2026-41378 🟡 Monitoruj

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired…

8.8 CVSS
0.2% EPSS
CVE-2026-41377 ⚪ Do wiadomości

OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install untrusted plugins when o…

4.6 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41376 ⚪ Do wiadomości

OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attackers can fetch thread-root and reply context mes…

5.4 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2026-41375 ⚪ Do wiadomości

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels. Attackers can bypas…

6.5 CVSS
0.1% EPSS
openclawauth-bypass 2026-04-28
CVE-2026-41373 ⚪ Do wiadomości

OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUILD_RUSTC, and CMAKE_C…

6.1 CVSS
0.0% EPSS
openclaw 2026-04-28
CVE-2025-13822 ⚪ Do wiadomości 🇵🇱 CERT.pl

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users an…

5.3 CVSS
0.1% EPSS
mcphubxauth-bypass 2026-04-14
CVE-2026-7324 🟡 Monitoruj

Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulner…

7.3 CVSS
0.0% EPSS
mozilla 2026-04-28
CVE-2026-38533 ⚪ Do wiadomości

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of o…

6.5 CVSS
0.1% EPSS
snipeitappexploit 2026-04-14
CVE-2026-23759 🟡 Monitoruj

Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection via the restricted shell accessed over Telnet or SSH. The shell 'ps' command does not perform proper…

7.2 CVSS
0.2% EPSS
rce 2026-03-17
CVE-2026-29522 ⚪ Do wiadomości

ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply directory traversal sequences…

0.0 CVSS
0.1% EPSS
lfipath-traversal 2026-03-16
CVE-2026-25075 🟡 Monitoruj

strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allows unauthenticated remote attackers to cause a denial of service by sending crafted AVP data with in…

7.5 CVSS
0.2% EPSS
dos 2026-03-23
CVE-2018-25206 🟡 Monitoruj

KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to e…

8.2 CVSS
0.1% EPSS
sql-injection 2026-03-26
CVE-2019-25648 ⚪ Do wiadomości

MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a …

6.2 CVSS
0.0% EPSS
buffer-overflowdos 2026-03-26
CVE-2026-29023 🟡 Monitoruj

Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker…

7.3 CVSS
0.1% EPSS
2026-03-09
CVE-2026-39304 🟡 Monitoruj
apps

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients…

7.5 CVSS
0.0% EPSS
apachedos 2026-04-10
CVE-2026-32845 🟡 Monitoruj

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB …

8.4 CVSS
0.0% EPSS
dos 2026-03-23
CVE-2019-25642 🟡 Monitoruj

Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads …

8.2 CVSS
0.1% EPSS
dossql-injection 2026-03-24
CVE-2019-25650 🟡 Monitoruj

River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Att…

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-26
CVE-2026-32857 🟡 Monitoruj

Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Playwright scraping service where network policy validation is applied only to the initial user-suppli…

8.6 CVSS
0.0% EPSS
ssrf 2026-03-26
CVE-2016-20037 🟡 Monitoruj

xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying overly long input strings that exceed buffer boundaries. Attackers can cr…

8.4 CVSS
0.0% EPSS
buffer-overflowdos 2026-03-28
CVE-2016-20038 🟡 Monitoruj

yTree 1.94-1.1 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an excessively long argument to the application. Attackers can craft a malicious comm…

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2016-20040 🟡 Monitoruj

TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM paramet…

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2016-20041 🟡 Monitoruj

Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with …

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2016-20042 🟡 Monitoruj

TRN 3.6-23 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the application. Attackers can craft a malicious command-line argument…

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2016-20046 🟡 Monitoruj

zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supp…

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2016-20048 🟡 Monitoruj

iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a malicious argument …

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2026-40499 🟡 Monitoruj

radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by embedding a newline byte in the PE section heade…

7.8 CVSS
0.2% EPSS
radareexploitrce 2026-04-15
CVE-2025-59375 🟡 Monitoruj

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

7.5 CVSS
0.0% EPSS
CVE-2026-29955 🟠 Łataj w tym tygodniu

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute shell commands, and the…

8.8 CVSS
0.1% EPSS
cloudarkexploitrce 2026-04-13
CVE-2019-25640 🟡 Monitoruj

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads…

8.2 CVSS
0.1% EPSS
dossql-injection 2026-03-24
CVE-2017-20226 🟡 Monitoruj

Mapscrn 2.0.3 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized input buffer. Attackers can craft a malicious buffer with junk data, retu…

8.4 CVSS
0.0% EPSS
buffer-overflowdos 2026-03-28
CVE-2018-25222 🟡 Monitoruj

SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings…

8.4 CVSS
0.0% EPSS
buffer-overflow 2026-03-28
CVE-2026-40504 🟠 Łataj w tym tygodniu

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scop…

9.8 CVSS
0.0% EPSS
buffer-overflowrce 2026-04-16
CVE-2026-40500 ⚪ Do wiadomości

ProcessWire CMS version 3.0.255 and prior contain a server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature that allows authenticated administrators to supply arbitrary URLs to the mo…

6.8 CVSS
0.0% EPSS
ssrf 2026-04-15
CVE-2026-33491 🟡 Monitoruj

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based buffer overflow vulnerability in the Zen C compiler allows attackers to cause a compiler crash or p…

7.8 CVSS
0.0% EPSS
CVE-2026-28207 ⚪ Do wiadomości

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shel…

6.6 CVSS
0.0% EPSS
zenc-langexploitrce 2026-02-26
CVE-2018-25203 🟡 Monitoruj

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests…

8.2 CVSS
0.1% EPSS
sql-injection 2026-03-26
CVE-2018-25207 🟡 Monitoruj

Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-sy…

7.1 CVSS
0.1% EPSS
CVE-2026-2332 🟡 Monitoruj

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * h…

7.4 CVSS
0.0% EPSS
eclipseexploit 2026-04-14
CVE-2026-21997 🟡 Monitoruj
appsos

Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allo…

8.5 CVSS
0.0% EPSS
oracle 2026-04-21
CVE-2026-5574 ⚪ Do wiadomości

A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing a…

6.5 CVSS
0.0% EPSS
technostrobeexploit 2026-04-05
CVE-2026-5398 🟡 Monitoruj
os

The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end…

8.4 CVSS
0.0% EPSS
freebsd 2026-04-22
CVE-2026-6386 ⚪ Do wiadomości
os

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which handled this failed to take into account the presence of 1GB largepage…

6.2 CVSS
0.0% EPSS
freebsd 2026-04-22
CVE-2026-22828 🟡 Monitoruj
network

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via…

8.1 CVSS
0.2% EPSS
CVE-2025-52641 ⚪ Do wiadomości

HCL AION is affected by a vulnerability where certain system behaviours may allow exploration of internal filesystem structures. Exposure of such information may provide insights into the underlying environment, which co…

2.9 CVSS
0.0% EPSS
hcltech 2026-04-15
CVE-2026-7320 🟡 Monitoruj

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird …

7.5 CVSS
0.0% EPSS
mozilla 2026-04-28
CVE-2026-7322 🟡 Monitoruj

Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to ru…

7.3 CVSS
0.1% EPSS
mozilla 2026-04-28
CVE-2026-22751 ⚪ Do wiadomości
cloud

Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects …

4.8 CVSS
0.0% EPSS
vmware 2026-04-21