6.1

CVSS3.1

CVE-2026-1011 - Stored Cross-Site Scripting in Altium Live Support Center Comment Endpoint

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via modified POST reque…

📅 Published: Jan. 15, 2026, 11:08 p.m. 🔄 Last Modified: Jan. 23, 2026, 8:26 p.m.

8

CVSS3.1

CVE-2026-1010 - Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow,…

📅 Published: Jan. 15, 2026, 11 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:31 p.m.

8.1

CVSS3.1

CVE-2026-22864 - Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension…

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefo…

📅 Published: Jan. 15, 2026, 10:58 p.m. 🔄 Last Modified: Jan. 21, 2026, 2:32 p.m.

9.2

CVSS4.0

CVE-2026-22863 - Deno node:crypto doesn't finalize cipher

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secret…

📅 Published: Jan. 15, 2026, 10:53 p.m. 🔄 Last Modified: Jan. 21, 2026, 2:35 p.m.

9

CVSS3.1

CVE-2026-1009 - Stored Cross-Site Scripting in Altium Live Forum Leading to Cross-Customer Data Exposure

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Success…

📅 Published: Jan. 15, 2026, 10:51 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:32 p.m.

5.9

CVSS3.1

CVE-2026-22045 - Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the A…

📅 Published: Jan. 15, 2026, 10:44 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:29 p.m.

6.5

CVSS3.1

CVE-2025-68671 - lakeFS is Missing Timestamp Validation in S3 Gateway Authentication

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not validate timestamps in authenticated requests, allowing replay attacks. Prior to 1.75.0, an attacker who captures a valid signed request (e.g., through network interception, logs,…

📅 Published: Jan. 15, 2026, 10:35 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:28 p.m.

7.6

CVSS3.1

CVE-2026-1008 - Stored Cross-Site Scripting in Altium Live User Profile Fields

A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient server-side input sanitization allows authenticated users to inject arbitrary HTML and JavaScript payloads using whitespace-based attribute parsing bypass techniques. The injected pa…

📅 Published: Jan. 15, 2026, 10:24 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:34 p.m.

7.5

CVSS3.1

CVE-2026-0915 - getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

📅 Published: Jan. 15, 2026, 10:08 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:36 p.m.

9.3

CVSS4.0

CVE-2023-7334 - Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore…

📅 Published: Jan. 15, 2026, 9:44 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:51 p.m.
Total resulsts: 329549
Page 161 of 32,955
« previous page » next page
Filters