8.6

CVSS4.0

CVE-2025-9120 - RCE vulnerability has been discovered in OpenTextโ„ข Carbonite Safe Server Backup.

Improper Control of Generation of Code ('Code Injection') vulnerability in OpenTextโ„ข Carbonite Safe Server Backup allows Code Injection.ย  The vulnerability could be exploited through an open port, potentially allowing unauthorized access. This issue affects Carbonite Safe Server Backup: through 6โ€ฆ

๐Ÿ“… Published: Feb. 24, 2026, 12:03 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2025-69253 - free5GC vulnerable to improper error handling in NEF with information exposure

free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of the User Data Repository are affected by Improper Error Handling with Information Exposure. The NEF component reliably leaks internal parsing error details (e.g., invalid character โ€ฆ

๐Ÿ“… Published: Feb. 24, 2026, 12:01 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 2:25 p.m.

9.8

CVSS3.1

CVE-2025-69985 -

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can byโ€ฆ

๐Ÿ“… Published: Feb. 24, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:39 p.m.

6.5

CVSS3.1

CVE-2025-67445 -

TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enfoโ€ฆ

๐Ÿ“… Published: Feb. 24, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 27, 2026, 7:16 p.m.

8.8

CVSS3.1

CVE-2025-63409 -

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

๐Ÿ“… Published: Feb. 24, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:42 p.m.

6.5

CVSS3.1

CVE-2026-3118 - Rhdh: graphql injection leading to platform-wide denial of service (dos) in rh developer hub orchesโ€ฆ

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, which disrupts backend query processing. This โ€ฆ

๐Ÿ“… Published: Feb. 24, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 8:37 p.m.

6.6

CVSS4.0

CVE-2025-69252 - free5GC has Null Pointer Dereference in UDM, Leading to Service Panic

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic (Denial of Service) by โ€ฆ

๐Ÿ“… Published: Feb. 23, 2026, 11:56 p.m. ๐Ÿ”„ Last Modified: Feb. 25, 2026, 4:46 p.m.

9.1

CVSS3.1

CVE-2024-58041 - Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions

Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Smolder::DB::Developer usโ€ฆ

๐Ÿ“… Published: Feb. 23, 2026, 11:54 p.m. ๐Ÿ”„ Last Modified: March 4, 2026, 2:22 a.m.

6.6

CVSS4.0

CVE-2025-69251 - free5GC has Improper Input Validation in UDM, Leading to Information Exposure

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, remote attackers can inject control characters (e.g., %00) into the ueId parameter, triggering internal URL parsing errors (netโ€ฆ

๐Ÿ“… Published: Feb. 23, 2026, 11:53 p.m. ๐Ÿ”„ Last Modified: Feb. 25, 2026, 4:46 p.m.

6.6

CVSS4.0

CVE-2025-69250 - free5GC has Improper Error Handling in UDM, Leading to Information Exposure

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks detailed internal error messages (e.g., strconv.ParseInt parsing errors) to remote clients when procโ€ฆ

๐Ÿ“… Published: Feb. 23, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: Feb. 25, 2026, 4:45 p.m.
Total resulsts: 349182
Page 1478 of 34,919
ยซ previous page ยป next page
Filters