4.7

CVSS3.1

CVE-2025-69725 - go-chi/chi: Go-chi/chi: Open Redirect vulnerability allows redirection to malicious websites

An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 2:16 p.m.

8.8

CVSS3.1

CVE-2025-69674 -

Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via the node_mac, node_opt, opt_param, and domainblk parameters of the mesh_node_config and domiainblk_config modules

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: Feb. 25, 2026, 9:16 p.m.

9.1

CVSS3.1

CVE-2025-55853 -

SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTM…

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 8:27 p.m.

9.8

CVSS3.1

CVE-2025-67305 -

In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These keys are identical across all deployments, allowing an attacker with network access to authenticate via SSH without a password. Once authenticated, the attacker can access the Pos…

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:34 a.m.

5.3

CVSS3.1

CVE-2026-26744 -

A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for valid and invalid usernames allowing an unauthenticated attacker to determine which usernames are re…

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 2:48 a.m.

3.8

CVSS3.1

CVE-2026-2733 - Org.keycloak/keycloak-services: keycloak: missing check on disabled client for docker registry prot…

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client β€œEnabled” setting to OFF does not fully prevent access. As a result, previously v…

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: March 6, 2026, 3:31 a.m.

9.8

CVSS3.1

CVE-2025-67304 -

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default configuration, the PostgreSQL service is accessible over the network on TCP port 5432. An attacker can use the hardcoded credentials to authenticate …

πŸ“… Published: Feb. 19, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:33 a.m.

6.7

CVSS4.0

CVE-2025-15585 -

Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration.

πŸ“… Published: Feb. 18, 2026, 11:44 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 5:20 p.m.

6.9

CVSS4.0

CVE-2026-2684 - Tsinghua Unigroup Electronic Archives System uploadFile.html unrestricted upload

A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordManage/uploadFile.html. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be la…

πŸ“… Published: Feb. 18, 2026, 11:32 p.m. πŸ”„ Last Modified: March 3, 2026, 4:44 p.m.

7.3

CVSS3.1

CVE-2026-25926 - Notepad++ has an Untrusted Search Path

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process wo…

πŸ“… Published: Feb. 18, 2026, 11:07 p.m. πŸ”„ Last Modified: Feb. 19, 2026, 6:32 p.m.
Total resulsts: 343981
Page 1062 of 34,399
Β« previous page Β» next page
Filters