8.2

CVSS4.0

CVE-2026-1953 - Stored Cross Site Scripting(XSS) in Nukegraphic CMS V3.1.2

Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality at /ngc-cms/user-edit-profile.php. The application fails to properly sanitize user input in the name field before storing it in the database and rendering it across multiple CMS โ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 6:33 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:15 p.m.

8.8

CVSS4.0

CVE-2025-15080 - Information Disclosure, Information Tampering, and Denial of Service (DoS) Vulnerability in Mitsubiโ€ฆ

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the affected product, write device data in the affected productโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 5:16 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-61732 - Potential code smuggling via doc comments in cmd/cgo

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

๐Ÿ“… Published: Feb. 5, 2026, 3:42 a.m. ๐Ÿ”„ Last Modified: Feb. 10, 2026, 3:17 p.m.

8.8

CVSS3.1

CVE-2025-10314 - Malicious Code Execution Vulnerability in Mitsubishi Small-Capacity UPS Shutdown Software FREQSHIP-โ€ฆ

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0 to 8.0.2 allows a local attacker to execute arbitrary code with system privileges by replacing service executable files (EXE) or DLLs in the installation directory with specially โ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 3:07 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-11730 -

A postโ€‘authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP series firmware versions from V5.35 through V5.41, USG FLEX series firmware versions from V5.35 through V5.41, USG FLEX 50(W) series firmware versions from V5.35 through V5.41, andโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 1:55 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2026-1898 - WeKan LDAP User Sync syncUser.js SyncLDAPBleed access control

A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It is possible to initiate the attack remotely. Upgrading to version 8.21 is able tโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:45 p.m.

5.3

CVSS4.0

CVE-2026-1897 - WeKan Position-History Tracking positionHistory.js PositionHistoryBleed authorization

A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from remote. Upgrading to versโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 12:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 p.m.

9

CVSS3.1

CVE-2025-68723 -

Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage feature, and (3) thโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 3:15 p.m.

8.8

CVSS3.1

CVE-2025-69906 -

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies on blacklist-based file extension validation and stores uploaded files directly in a web-accessible directory. Under typical server configurations, this can allow an attacker to upโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 11, 2026, 7:07 p.m.

7.2

CVSS3.1

CVE-2025-70073 -

An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function

๐Ÿ“… Published: Feb. 5, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 12, 2026, 5:30 p.m.
Total resulsts: 347988
Page 1672 of 34,799
ยซ previous page ยป next page
Filters