8.5

CVSS4.0

CVE-2021-47822 - DiskBoss Service 12.2.18 - 'diskbsa.exe' Unquoted Service Path

DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level a…

πŸ“… Published: Jan. 16, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

4.6

CVSS4.0

CVE-2021-47821 - RarmaRadio 2.72.8 - Denial of Service

RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing network configuration fields with large character buffers. Attackers can generate a 100,000 character buffer and paste it into multiple network settings fields to trigger appli…

πŸ“… Published: Jan. 16, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

5.1

CVSS4.0

CVE-2021-47820 - Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF)

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.

πŸ“… Published: Jan. 16, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

4.6

CVSS4.0

CVE-2021-47818 - DupTerminator 1.4.5639.37199 - Denial of Service

DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application by inputting a long character string in the Excluded text box. Attackers can generate a payload of 8000 repeated characters to trigger the application to stop working on Windows 10.

πŸ“… Published: Jan. 16, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

5.3

CVSS4.0

CVE-2021-47816 - Thecus N4800Eco Nas Server Control Panel - Command Injection

Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands wit…

πŸ“… Published: Jan. 16, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

8.1

CVSS3.1

CVE-2026-23535 - wlc Path traversal: Unsanitized API slugs in download command

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

πŸ“… Published: Jan. 16, 2026, 7:08 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

7.5

CVSS3.1

CVE-2026-23490 - pyasn1 has a DoS vulnerability in decoder

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

πŸ“… Published: Jan. 16, 2026, 7:03 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

7.8

CVSS3.1

CVE-2025-48647 -

In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Jan. 16, 2026, 6:19 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

7.4

CVSS3.1

CVE-2025-15032 - CVE-2025-15032: Increased Spoofing risk; custom new window missing about:blank

Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

πŸ“… Published: Jan. 16, 2026, 6:11 p.m. πŸ”„ Last Modified: Jan. 19, 2026, 9:20 a.m.

8.7

CVSS4.0

CVE-2026-0629 - Authentication Bypass in Password Recovery Feature via Local Web App on Multiple VIGI Cameras

Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attackers can gain full administrative access to the device, comprom…

πŸ“… Published: Jan. 16, 2026, 5:24 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 10:15 a.m.
Total resulsts: 329470
Page 139 of 32,947
Β« previous page Β» next page
Filters