9.4

CVSS3.1

CVE-2025-4319 - Improper Access Control in Birebirsoft's Sufirmam

Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026.Β NOTE: The vend…

πŸ“… Published: Jan. 23, 2026, 12:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-2204 - XSS in Tapandsign Technologies' Tap&Sign App

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tapandsign Technologies Software Inc. Tap&Sign allows Cross-Site Scripting (XSS).This issue affects Tap&Sign: through 23012026. NOTE: The vendor was contacted early about this disclosure bu…

πŸ“… Published: Jan. 23, 2026, 11:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-46699 -

Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

πŸ“… Published: Jan. 23, 2026, 9:53 a.m. πŸ”„ Last Modified: Jan. 28, 2026, 6:59 p.m.

5.5

CVSS3.1

CVE-2026-22276 - Cleartext Storage of Sensitive Information in Dell ECS and ObjectScale

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

πŸ“… Published: Jan. 23, 2026, 9:42 a.m. πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.

4.4

CVSS3.1

CVE-2026-22275 - Dell ECS/ObjScale Sensitive Information Exposure via Source Code Inclusion

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sensitive Information in Source Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

πŸ“… Published: Jan. 23, 2026, 9:34 a.m. πŸ”„ Last Modified: April 18, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-22274 - Cleartext Transmission of Sensitive Information in Dell ObjectScale Fabric Syslog

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability in the Fabric Syslog. An unauthenticated attacker with remote access could potentially exploit this vulnerability to intercept and mod…

πŸ“… Published: Jan. 23, 2026, 9:25 a.m. πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.

8.8

CVSS3.1

CVE-2026-22273 -

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: Jan. 23, 2026, 9:14 a.m. πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.

7.5

CVSS3.1

CVE-2026-22271 - Cleartext Transmission of Sensitive Information in Dell ECS and ObjectScale

Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

πŸ“… Published: Jan. 23, 2026, 8:54 a.m. πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.

9.3

CVSS4.0

CVE-2026-1364 - JNC|IAQS and I6 - Missing Authentication

IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system administrative functionalities.

πŸ“… Published: Jan. 23, 2026, 8:41 a.m. πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.

9.3

CVSS4.0

CVE-2026-1363 - JNC|IAQS and I6 - Client-Side Enforcement of Server-Side Security

IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.

πŸ“… Published: Jan. 23, 2026, 8:37 a.m. πŸ”„ Last Modified: April 18, 2026, 3:15 a.m.
Total resulsts: 346617
Page 1721 of 34,662
Β« previous page Β» next page
Filters