7.1

CVSS3.1

CVE-2025-36247 - IBM Db2 XML External Entity Reference

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume me…

📅 Published: Feb. 17, 2026, 5:13 p.m. 🔄 Last Modified: Feb. 18, 2026, 7:23 p.m.

5.3

CVSS3.1

CVE-2025-36425 - IBM Db2 Information Disclosure

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to obtain sensitive information under specific HADR configuration.

📅 Published: Feb. 17, 2026, 5:13 p.m. 🔄 Last Modified: Feb. 18, 2026, 7:22 p.m.

6.5

CVSS3.1

CVE-2025-13867 - IBM Db2 Denial of Service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic

📅 Published: Feb. 17, 2026, 5:13 p.m. 🔄 Last Modified: Feb. 18, 2026, 7:30 p.m.

6.5

CVSS3.1

CVE-2025-14689 - IBM Db2 Denial of Service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 12.1.0 through 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic with federated objects.

📅 Published: Feb. 17, 2026, 5:12 p.m. 🔄 Last Modified: Feb. 18, 2026, 7:23 p.m.

6.3

CVSS4.0

CVE-2026-2618 - Beetel 777VR1 SSH Service risky encryption

A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Service. This manipulation causes risky cryptographic algorithm. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitabil…

📅 Published: Feb. 17, 2026, 4:32 p.m. 🔄 Last Modified: Feb. 23, 2026, 10:14 a.m.

8.5

CVSS4.0

CVE-2026-23648 - Glory RBG-100 Recycler System Local Privilege Escalation via Insecure File Permissions

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can replace or modify these…

📅 Published: Feb. 17, 2026, 4:30 p.m. 🔄 Last Modified: Feb. 18, 2026, 5:52 p.m.

9.3

CVSS4.0

CVE-2026-23647 - Glory RBG-100 Recycler System Hard-coded OS Credentials

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded pa…

📅 Published: Feb. 17, 2026, 4:30 p.m. 🔄 Last Modified: Feb. 18, 2026, 5:52 p.m.

5.3

CVSS4.0

CVE-2026-2617 - Beetel 777VR1 Telnet Service/SSH Service insecure default initialization of resource

A vulnerability was found in Beetel 777VR1 up to 01.00.09. This affects an unknown function of the component Telnet Service/SSH Service. The manipulation results in insecure default initialization of resource. The attack can only be performed from the local network. The exploit has been made public…

📅 Published: Feb. 17, 2026, 3:32 p.m. 🔄 Last Modified: Feb. 23, 2026, 10:13 a.m.

6.5

CVSS3.1

CVE-2024-31118 - WordPress SP Project & Document Manager plugin <= 4.70 - Broken Access Control to XSS vulnerability

Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70.

📅 Published: Feb. 17, 2026, 3:04 p.m. 🔄 Last Modified: Feb. 18, 2026, 5:52 p.m.

8.7

CVSS4.0

CVE-2026-2616 - Beetel 777VR1 Web Management hard-coded credentials

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface. The manipulation leads to hard-coded credentials. The attack needs to be initiated within the local network. The exploit has been disclosed to the p…

📅 Published: Feb. 17, 2026, 3:02 p.m. 🔄 Last Modified: Feb. 23, 2026, 10:13 a.m.
Total resulsts: 343919
Page 1086 of 34,392
« previous page » next page
Filters