7.1

CVSS3.1

CVE-2026-22249 - Docmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability …

πŸ“… Published: Jan. 15, 2026, 6:43 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 3:44 p.m.

8.2

CVSS4.0

CVE-2026-22803 - SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a…

πŸ“… Published: Jan. 15, 2026, 6:37 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:34 p.m.

8.4

CVSS4.0

CVE-2025-67647 - SvelteKit Denial of service and possible SSRF when using prerendering

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability results in a DoS whe…

πŸ“… Published: Jan. 15, 2026, 6:33 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:37 p.m.

8.4

CVSS4.0

CVE-2025-13845 -

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

πŸ“… Published: Jan. 15, 2026, 6:33 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.4

CVSS4.0

CVE-2025-13844 -

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

πŸ“… Published: Jan. 15, 2026, 6:28 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

7.1

CVSS3.1

CVE-2025-36911 -

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Jan. 15, 2026, 5:41 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 9:52 p.m.

6.3

CVSS4.0

CVE-2025-9014 - Null Pointer Dereference Vulnerability on TL-WR841N

A Null Pointer Dereference vulnerability exists in the referer header check of theΒ web portal of TP-Link TL-WR841N v14, caused by improper input validation.Β  A remote, unauthenticated attacker can exploit this flaw andΒ cause Denial of Service on the web portal service.This issue affects TL-WR841N v…

πŸ“… Published: Jan. 15, 2026, 5:36 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

4.3

CVSS3.1

CVE-2026-23494 - Pimcore is Missing Function Level Authorization on "Static Routes" Listing

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listing static routes. In Pimcore, static routes are custom URL patterns defined via …

πŸ“… Published: Jan. 15, 2026, 4:52 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 9:47 p.m.

9.3

CVSS4.0

CVE-2025-62193 - NOAA PMEL Live Access Server (LAS) PyFerret command injection

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of 'gov.noaa.pmel.tmap.l…

πŸ“… Published: Jan. 15, 2026, 4:44 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.6

CVSS3.1

CVE-2026-23493 - Pimcore ENV Variables and Cookie Informations are exposed in http_error_log

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed or recovered through…

πŸ“… Published: Jan. 15, 2026, 4:38 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 9:48 p.m.
Total resulsts: 329057
Page 117 of 32,906
Β« previous page Β» next page
Filters