8.7

CVSS4.0

CVE-2026-2067 - UTT 进取 520W formTimeGroupConfig strcpy buffer overflow

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publi…

📅 Published: Feb. 6, 2026, 9:02 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:02 p.m.

8.6

CVSS3.1

CVE-2026-25580 - Pydantic AI Affected by Server-Side Request Forgery (SSRF) in URL Download Handling

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to before 1.56.0, aServer-Side Request Forgery (SSRF) vulnerability exists in Pydantic AI's URL download functionality. When applications accept message history from untrusted sources, at…

📅 Published: Feb. 6, 2026, 9:01 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:01 p.m.

5.4

CVSS3.1

CVE-2026-25581 - SCEditor affected by DOM XSS via emoticon URL/HTML injection

SCEditor is a lightweight WYSIWYG BBCode and XHTML editor. Prior to 3.2.1, if an attacker has the ability control configuration options passed to sceditor.create(), like emoticons, charset, etc. then it's possible for them to trigger an XSS attack due to lack of sanitisation of configuration option…

📅 Published: Feb. 6, 2026, 8:58 p.m. 🔄 Last Modified: Feb. 6, 2026, 8:58 p.m.

8.4

CVSS3.1

CVE-2026-25593 - OpenClaw Affected by Unauthenticated Local RCE via WebSocket config.apply

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket API to write config via config.apply and set unsafe cliPath values that were later used for command discovery, enabling command injection as the gateway user. This vulnerability …

📅 Published: Feb. 6, 2026, 8:56 p.m. 🔄 Last Modified: Feb. 6, 2026, 8:56 p.m.

5.3

CVSS3.1

CVE-2026-25597 - PrestaShop has a time based enumeration in FO login form

PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measu…

📅 Published: Feb. 6, 2026, 8:47 p.m. 🔄 Last Modified: Feb. 6, 2026, 8:47 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here