5.1

CVSS4.0

CVE-2019-25397 - IPFire 2.21 Core Update 127 Cross-Site Scripting via hosts.cgi

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious scripts through unvalidated parameters. Attackers can submit POST requests with script payloads in the KEY1, IP, HOST, or DOM parameters to e…

📅 Published: Feb. 18, 2026, 8:59 p.m. 🔄 Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25396 - IPFire 2.21 Core Update 127 Reflected XSS via updatexlrator.cgi

IPFire 2.21 Core Update 127 contains a reflected cross-site scripting vulnerability in the updatexlrator.cgi script that allows attackers to inject malicious scripts through POST parameters. Attackers can submit crafted requests with script payloads in the MAX_DISK_USAGE or MAX_DOWNLOAD_RATE parame…

📅 Published: Feb. 18, 2026, 8:59 p.m. 🔄 Last Modified: March 5, 2026, 1:26 a.m.

5.7

CVSS3.1

CVE-2026-24746 - InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePlane version 1.7.0. In the Editing Quotes function, the application does not validate user input at th…

📅 Published: Feb. 18, 2026, 8:51 p.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

7.1

CVSS4.0

CVE-2026-1999 - Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unaut…

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a repository without having push access by exploiting an authorization bypass in the enable_auto_merge mutation for pull requests. This issue only affect…

📅 Published: Feb. 18, 2026, 8:44 p.m. 🔄 Last Modified: April 15, 2026, 5:15 p.m.

6

CVSS4.0

CVE-2026-1355 - Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository M…

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration upload endpoint. By supplying the migration identif…

📅 Published: Feb. 18, 2026, 8:42 p.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

7.6

CVSS4.0

CVE-2026-0573 - Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that a…

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages API insecurely followed HTTP redirects when fetching artifact URLs, preserving the authorization header containing a pr…

📅 Published: Feb. 18, 2026, 8:37 p.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

6.9

CVSS4.0

CVE-2026-2668 - Rongzhitong Visual Integrated Command and Dispatch Platform User add access control

A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper access controls. The attack may be launched remotely. The e…

📅 Published: Feb. 18, 2026, 8:32 p.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

6.9

CVSS4.0

CVE-2026-2667 - Rongzhitong Visual Integrated Command and Dispatch Platform api access control

A vulnerability has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. The impacted element is an unknown function of the file /dispatch/api?cmd=userinfo. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has…

📅 Published: Feb. 18, 2026, 8:32 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

5.3

CVSS3.1

CVE-2025-10256 - Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file wi…

📅 Published: Feb. 18, 2026, 8:26 p.m. 🔄 Last Modified: Feb. 26, 2026, 10:33 p.m.

3.7

CVSS3.1

CVE-2026-2708 - Libsoup: libsoup: http request smuggling via duplicate content-length headers

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an atta…

📅 Published: Feb. 18, 2026, 8:13 p.m. 🔄 Last Modified: May 4, 2026, 6:28 p.m.
Total resulsts: 349182
Page 1586 of 34,919
« previous page » next page
Filters