6.7

CVSS4.0

CVE-2026-24056 - pnpm has symlink traversal in file:/git dependencies

pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package containing a symlink to an absolute path (e.g., `/etc/passwd`, `…

📅 Published: Jan. 26, 2026, 9:59 p.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.

6.5

CVSS3.1

CVE-2026-23890 - pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validation, and after scope normalization, path traversal…

📅 Published: Jan. 26, 2026, 9:53 p.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.

6.5

CVSS3.1

CVE-2026-23889 - pnpm has Windows-specific tarball Path Traversal

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Windows, backslashes are directory separat…

📅 Published: Jan. 26, 2026, 9:50 p.m. 🔄 Last Modified: April 18, 2026, 3 p.m.

7.2

CVSS3.1

CVE-2025-59473 -

SQL Injection vulnerability in the Structure for Admin authenticated user

📅 Published: Jan. 26, 2026, 9:43 p.m. 🔄 Last Modified: Feb. 13, 2026, 2:22 p.m.

5.9

CVSS3.1

CVE-2025-59471 - next: NextJS Denial of Service in Image Optimizer

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cau…

📅 Published: Jan. 26, 2026, 9:43 p.m. 🔄 Last Modified: Feb. 13, 2026, 3:03 p.m.

5.9

CVSS3.1

CVE-2025-59472 - next: NextJS Denial of Service in Partial Pre Rendering

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely relat…

📅 Published: Jan. 26, 2026, 9:43 p.m. 🔄 Last Modified: Feb. 24, 2026, 6:24 p.m.

6.5

CVSS3.1

CVE-2026-23888 - pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../` or absolute paths tha…

📅 Published: Jan. 26, 2026, 9:37 p.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.

4.8

CVSS4.0

CVE-2026-1444 - iJason-Liu Books_Manager add_book_check.php cross site scripting

A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects an unknown part of the file controllers/books_center/add_book_check.php. Such manipulation of the argument mark leads to cross site scripting. The attack can be launched remotely.…

📅 Published: Jan. 26, 2026, 9:32 p.m. 🔄 Last Modified: April 18, 2026, 8:15 p.m.

9.8

CVSS3.1

CVE-2026-22709 - vm2 has a Sandbox Escape

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In lib/setup-sandbox.js, the callback function of `localPromise…

📅 Published: Jan. 26, 2026, 9:32 p.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.

9.3

CVSS4.0

CVE-2026-22696 - dcap-qvl has Missing Verification for QE Identity

dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 involves a critical gap in the cryptographic verification process within the dcap-qvl. The library fetches QE Identity collateral (including qe_identity…

📅 Published: Jan. 26, 2026, 9:28 p.m. 🔄 Last Modified: April 18, 2026, 2:45 a.m.
Total resulsts: 346783
Page 1704 of 34,679
« previous page » next page
Filters