9.2

CVSS4.0

CVE-2026-1803 - Ziroom ZHOME A0101 Dropbear SSH Service default credentials

A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitability is …

πŸ“… Published: Feb. 3, 2026, 8:02 p.m. πŸ”„ Last Modified: April 18, 2026, 2:15 p.m.

7.8

CVSS3.1

CVE-2026-24149 - Code Injection Vulnerability in NVIDIA Megatron-LM Leading to Code Execution

NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, data tampering.

πŸ“… Published: Feb. 3, 2026, 7:55 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

1.7

CVSS4.0

CVE-2025-64438 - Fast-DDS: Unbounded GAP range triggers OOM DoS under RELIABLE QoS

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely triggerable Out-of-Memory (OOM) denial-of-service exists in Fast -DDS when processing RTPS GAP submessages under RELIABLE Qo…

πŸ“… Published: Feb. 3, 2026, 7:32 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:02 p.m.

1.7

CVSS4.0

CVE-2025-64098 - FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is e…

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OO…

πŸ“… Published: Feb. 3, 2026, 7:29 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:15 p.m.

7.2

CVSS4.0

CVE-2025-62799 - FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE)

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a heap buffer overflow exists in the Fast-DDS DATA_FRAG receive path. An un authenticated sender can transmit a single malformed RTPS D…

πŸ“… Published: Feb. 3, 2026, 7:26 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:11 p.m.

1.7

CVSS4.0

CVE-2025-62603 - FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is the DDS Security control-message container that carries not only the handshake but also on going security-control traffic after the handshake, such as…

πŸ“… Published: Feb. 3, 2026, 7:23 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:11 p.m.

4.7

CVSS3.1

CVE-2026-25616 - Blesta Input Validation XSS Vulnerability

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

πŸ“… Published: Feb. 3, 2026, 7:21 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

1.7

CVSS4.0

CVE-2025-62602 - FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is e…

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overfl…

πŸ“… Published: Feb. 3, 2026, 7:20 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:12 p.m.

7.2

CVSS3.1

CVE-2026-25615 - Object Injection Vulnerability in Blesta Versions 3.x to 5.x Before 5.13.3

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.

πŸ“… Published: Feb. 3, 2026, 7:18 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.

7.5

CVSS3.1

CVE-2026-25614 - Object Injection in Blesta 3.x–5.x Allowing Remote Code Execution

Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.

πŸ“… Published: Feb. 3, 2026, 7:16 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 a.m.
Total resulsts: 347814
Page 1688 of 34,782
Β« previous page Β» next page
Filters