4.3

CVSS3.1

CVE-2026-25916 -

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

๐Ÿ“… Published: Feb. 9, 2026, 8:14 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

8.6

CVSS3.1

CVE-2025-7799 - Reflected XSS in Zirve Information Technologies' e-Taxpayer Accounting Website

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS.This issue affects e-Taxpayer Accounting Website: through 07082025.

๐Ÿ“… Published: Feb. 9, 2026, 8:11 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

6.9

CVSS4.0

CVE-2026-2223 - code-projects Online Reviewer System index.php sql injection

A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiateโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:02 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

9.8

CVSS3.1

CVE-2026-22906 - Hardcoded Key Allows Credential Disclosure

User credentials are stored using AESโ€‘ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.

๐Ÿ“… Published: Feb. 9, 2026, 7:40 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 4:08 p.m.

7.5

CVSS3.1

CVE-2026-22905 - Authentication Bypass via URI Traversal

An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path traversal sequences (e.g., /js/../cgi-bin/post.cgi), gaining unauthorized access to protected CGI endpoints and configuration downloads.

๐Ÿ“… Published: Feb. 9, 2026, 7:40 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 3:33 p.m.

9.8

CVSS3.1

CVE-2026-22904 - Stack Overflow via Oversized Cookie Fields in lighttpd

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denialโ€‘ofโ€‘service condition and possible remote code execution.

๐Ÿ“… Published: Feb. 9, 2026, 7:40 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 3:34 p.m.

9.8

CVSS3.1

CVE-2026-22903 - Stack Overflow via SESSIONID Cookie in lighttpd

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

๐Ÿ“… Published: Feb. 9, 2026, 7:39 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 3:36 p.m.

4.8

CVSS4.0

CVE-2026-2222 - code-projects Online Reviewer System btn_functions.php cross site scripting

A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack maโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 7:32 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 3:38 p.m.

8.7

CVSS4.0

CVE-2026-2236 - HGiga๏ฝœC&Cm@il - SQL Injection

C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

๐Ÿ“… Published: Feb. 9, 2026, 7:20 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 3:42 p.m.

7.1

CVSS4.0

CVE-2026-2235 - HGiga๏ฝœC&Cm@il - SQL Injection

C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

๐Ÿ“… Published: Feb. 9, 2026, 7:17 a.m. ๐Ÿ”„ Last Modified: Feb. 9, 2026, 3:43 p.m.
Total resulsts: 331825
Page 17 of 33,183
ยซ previous page ยป next page
Filters