Overview
- VMware
- Spring AI
- Spring AI
18 Mar 2026
Published
19 Mar 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.02%
KEV
Description
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands.
The vulnerability exists due to missing input sanitization.
Statistics
- 1 Post
Last activity: 5 hours ago
Overview
- Ubiquiti Inc
- UniFi Network Application
19 Mar 2026
Published
19 Mar 2026
Updated
CVSS v3.1
CRITICAL (10.0)
EPSS
0.03%
KEV
Description
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.
Statistics
- 1 Post
Last activity: 4 hours ago
Bluesky
Overview
- Microsoft
- Microsoft Copilot
19 Mar 2026
Published
21 Mar 2026
Updated
CVSS v3.1
MEDIUM (6.5)
EPSS
0.08%
KEV
Description
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Statistics
- 1 Post
- 1 Interaction
Last activity: 6 hours ago
Overview
Description
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Statistics
- 1 Post
- 1 Interaction
Last activity: 2 hours ago
Fediverse
https://www.wacoca.com/news/2796427/ 【セキュリティ ニュース】「Chrome」アップデート、クリティカル含む脆弱性26件を修正(1ページ目 / 全1ページ):Security NEXT #Chrome #Chrome146 #CVE20264439 #CVE20264441 #Google #Science&Technology #ScienceNews #Security #TechnologyNews #UseAfterFree #V8 #WebGL #クリティカル脆弱性 #セキュリティ #セキュリティアップデート #テクノロジー #ニュース #対策 #科学 #科学&テクノロジー
Overview
- ultrajson
- ultrajson
20 Mar 2026
Published
20 Mar 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.05%
KEV
Description
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus an additional NULL byte. The leak occurs irrespective of whether the integer parses successfully or is rejected due to having more than sys.get_int_max_str_digits() digits, meaning that any sized leak per malicious JSON can be achieved provided that there is no limit on the overall size of the payload. Any service that calls ujson.load()/ujson.loads()/ujson.decode() on untrusted inputs is affected and vulnerable to denial of service attacks. This issue has been fixed in version 5.12.0.
Statistics
- 1 Post
- 1 Interaction
Last activity: 12 hours ago
Overview
Description
Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Statistics
- 1 Post
- 1 Interaction
Last activity: 2 hours ago
Fediverse
https://www.wacoca.com/news/2796427/ 【セキュリティ ニュース】「Chrome」アップデート、クリティカル含む脆弱性26件を修正(1ページ目 / 全1ページ):Security NEXT #Chrome #Chrome146 #CVE20264439 #CVE20264441 #Google #Science&Technology #ScienceNews #Security #TechnologyNews #UseAfterFree #V8 #WebGL #クリティカル脆弱性 #セキュリティ #セキュリティアップデート #テクノロジー #ニュース #対策 #科学 #科学&テクノロジー
Overview
- Microsoft
- Microsoft 365 Copilot
19 Mar 2026
Published
21 Mar 2026
Updated
CVSS v3.1
MEDIUM (5.3)
EPSS
0.04%
KEV
Description
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Statistics
- 1 Post
- 1 Interaction
Last activity: 6 hours ago
Description
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Statistics
- 1 Post
Last activity: 10 hours ago
Description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Statistics
- 1 Post
Last activity: 10 hours ago