6.5

CVSS3.1

CVE-2026-2436 - Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been free…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

2.9

CVSS3.1

CVE-2025-69873 - ajv: ReDoS via $data reference

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor witho…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: March 3, 2026, 5:25 p.m.

9.8

CVSS3.1

CVE-2025-67135 -

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 12, 2026, 4:16 p.m.

8.1

CVSS3.1

CVE-2025-69871 -

A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote attackers to bypass usage li…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 12, 2026, 4:16 p.m.

7.8

CVSS3.1

CVE-2025-70083 -

An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirName into the local buffer DirWithSep using strcpy. The size of this buffer is OS_MAX_PATH_LEN. If the length of DirName …

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 3:03 p.m.

10

CVSS3.1

CVE-2025-64075 -

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 9:46 p.m.

8.1

CVSS3.1

CVE-2025-65128 -

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 10:18 p.m.

8.8

CVSS3.1

CVE-2024-50619 -

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account informati…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 9:39 p.m.

7

CVSS3.1

CVE-2026-26158 - Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive …

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to pri…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 2 p.m.

7

CVSS3.1

CVE-2026-26157 - Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitiz…

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially …

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 8, 2026, 2 p.m.
Total resulsts: 343183
Page 1097 of 34,319
Β« previous page Β» next page
Filters