7.8

CVSS3.1

CVE-2026-25582 - iccDEV vulnerable to Heap Buffer Overflow in CIccIO::WriteUInt16Float()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.3, there is a heap buffer overflow (read) vulnerability in CIccIO::WriteUInt16Float() when converting malformed XML to ICC profiles via…

πŸ“… Published: Feb. 4, 2026, 10:07 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 6:48 p.m.

5.5

CVSS4.0

CVE-2026-25541 - Bytes is vulnerable to integer overflow in BytesMut::reserve

Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. When new_cap + offset …

πŸ“… Published: Feb. 4, 2026, 10:03 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 8:13 p.m.

2.3

CVSS4.0

CVE-2026-1892 - WeKan REST API boards.js setBoardOrgs improper authorization

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improper authorization. The attack may be launched remo…

πŸ“… Published: Feb. 4, 2026, 10:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

6.1

CVSS3.1

CVE-2026-25578 - Navidrome is vulnerable to XSS via comment from song metadata

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the frontend allows a malicious attacker to inject code through the comment metadata of a song to exfiltrate user credentials. This issue has been patched in …

πŸ“… Published: Feb. 4, 2026, 9:58 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 7:03 p.m.

9.2

CVSS4.0

CVE-2026-25579 - Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/res…

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/<token>). When processing such requests,…

πŸ“… Published: Feb. 4, 2026, 9:58 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 7:01 p.m.

8.8

CVSS4.0

CVE-2026-25575 - NavigaTUM has a Path Traversal Vulnerability in the propose_edits functionality

NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path traversal vulnerability in the propose_edits endpoint allows unauthenticated users to overwrite files in directories writable by the application user (e.g., /cdn). By supplying u…

πŸ“… Published: Feb. 4, 2026, 9:54 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 7:10 p.m.

9.2

CVSS4.0

CVE-2026-25547 - Uncontrolled Resource Consumption in @isaacs/brace-expansion

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, t…

πŸ“… Published: Feb. 4, 2026, 9:51 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 2:57 p.m.

7.8

CVSS3.1

CVE-2026-25546 - Godot MCP is vulnerable to Command Injection via unsanitized projectPath

Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerability in godot-mcp allows remote code execution. The executeOperation function passed user-controlled input (e.g., projectPath) directly to exec(), whic…

πŸ“… Published: Feb. 4, 2026, 9:48 p.m. πŸ”„ Last Modified: March 18, 2026, 2:25 p.m.

6.3

CVSS4.0

CVE-2026-25543 - HtmlSanitizer has a bypass via template tag

HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its cont…

πŸ“… Published: Feb. 4, 2026, 9:45 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 9:29 p.m.

6.5

CVSS3.1

CVE-2026-25540 - Mastodon's signature-dependent ActivityPub collection responses cached under signature-independent …

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mastodon is vulnerable to web cache poisoning via `Rails.cache. When AUTHORIZED_FETCH is enabled, the ActivityPub endpoints for pinned posts and featured hashtags have contents that …

πŸ“… Published: Feb. 4, 2026, 9:42 p.m. πŸ”„ Last Modified: Feb. 20, 2026, 9:02 p.m.
Total resulsts: 342218
Page 1101 of 34,222
Β« previous page Β» next page
Filters