5.9

CVSS3.1

CVE-2026-22045 - Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the A…

📅 Published: Jan. 15, 2026, 10:44 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:29 p.m.

6.5

CVSS3.1

CVE-2025-68671 - lakeFS is Missing Timestamp Validation in S3 Gateway Authentication

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs,…

📅 Published: Jan. 15, 2026, 10:35 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:28 p.m.

7.6

CVSS3.1

CVE-2026-1008 - Stored Cross-Site Scripting in Altium Live User Profile Fields

A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization allows authenticated users to inject arbitrary HTML and JavaScript payloads using whitespace-based attribute parsing bypass techniques. The injected pa…

📅 Published: Jan. 15, 2026, 10:24 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:34 p.m.

7.5

CVSS3.1

CVE-2026-0915 - getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

📅 Published: Jan. 15, 2026, 10:08 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:36 p.m.

9.3

CVSS4.0

CVE-2023-7334 - Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore…

📅 Published: Jan. 15, 2026, 9:44 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:51 p.m.

9.3

CVSS4.0

CVE-2011-10041 - Uploadify <= 1.0 Unauthenticated Arbitrary File Upload

Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An unauthenticated remote attacker can upload arbitrary files to the affected WordPress site, which may allow remote code execution b…

📅 Published: Jan. 15, 2026, 9:44 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:16 p.m.

6.9

CVSS4.0

CVE-2026-1002 - Eclipse Vert.x Web static handler file access denial

The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI. The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used …

📅 Published: Jan. 15, 2026, 8:50 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

7.1

CVSS4.0

CVE-2026-21921 - Junos OS and Junos OS Evolved: When telemetry collectors are frequently subscribing and unsubscribi…

A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker authenticated with low privileges to cause a Denial-of-Service (DoS). When telemetry collectors are frequently subscribing and unsubscribing to sensors …

📅 Published: Jan. 15, 2026, 8:28 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:52 p.m.

8.7

CVSS4.0

CVE-2026-21920 - Junos OS: SRX Series: If a specific request is processed by the DNS subsystem flowd will crash

An Unchecked Return Value vulnerability in the DNS module of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an SRX Series device configured for DNS processing, receives a specifically formatted DNS request flowd w…

📅 Published: Jan. 15, 2026, 8:28 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:51 p.m.

8.7

CVSS4.0

CVE-2026-21918 - Junos OS: SRX and MX Series: When TCP packets occur in a specific sequence flowd crashes

A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, when during TCP session establishment a specific sequence of …

📅 Published: Jan. 15, 2026, 8:27 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:41 p.m.
Total resulsts: 329524
Page 159 of 32,953
« previous page » next page
Filters