7.1

CVSS4.0

CVE-2025-12679 - Plain text pbe key visible in audit log during Brocade SANnav migration from 2.4.0a to 3.0.0

A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the system audit log file. The vulnerability could allow a remote authenticated attacker with access to the audit logs to access the pbe key. Note: The vulnerability is only triggered โ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:41 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 1:05 a.m.

9.8

CVSS3.1

CVE-2025-66480 - Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an endpoint (/fs) that handlesโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:33 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 1:01 a.m.

5.4

CVSS3.1

CVE-2025-69207 - Khoj has an IDOR in Notion OAuth Flow Enables Index Poisoning

Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiateโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:16 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2026, 8:34 p.m.

9.8

CVSS3.1

CVE-2026-22778 - vLLM leaks a heap address when PIL throws an error

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guessโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:09 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

0.0

CVE-2026-1783 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: Feb. 2, 2026, 9:03 p.m. ๐Ÿ”„ Last Modified: Feb. 16, 2026, 3:54 p.m.

7.1

CVSS3.1

CVE-2025-13096 - XML eXternal Entity injection (XXE) vulnerability affect IBM Business Automation Workflow -

IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. Aย remote atโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:56 p.m. ๐Ÿ”„ Last Modified: Feb. 12, 2026, 7:01 p.m.

4.4

CVSS3.1

CVE-2026-22780 - Rizin has a heap overflow on mach0_chained_fixups.c

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.

๐Ÿ“… Published: Feb. 2, 2026, 8:52 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:30 p.m.

6

CVSS4.0

CVE-2025-12680 - Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the databasโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:50 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 1:02 a.m.

5.4

CVSS3.1

CVE-2026-23476 - FacturaScripts Affected by Reflected XSS

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passinโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:49 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

10

CVSS3.1

CVE-2026-23515 - RCE - Command Injection in Signal K set-system-time plugin

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated usโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:43 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.
Total resulsts: 347635
Page 1701 of 34,764
ยซ previous page ยป next page
Filters