7.5

CVSS3.1

CVE-2026-22774 - devalue vulnerable to denial of service due to memory exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

πŸ“… Published: Jan. 15, 2026, 6:53 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:28 p.m.

6.6

CVSS4.0

CVE-2026-0227 - PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

πŸ“… Published: Jan. 15, 2026, 6:45 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 7:11 p.m.

7.1

CVSS3.1

CVE-2026-22249 - Docmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability …

πŸ“… Published: Jan. 15, 2026, 6:43 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 3:44 p.m.

8.2

CVSS4.0

CVE-2026-22803 - SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a…

πŸ“… Published: Jan. 15, 2026, 6:37 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:34 p.m.

8.4

CVSS4.0

CVE-2025-67647 - SvelteKit Denial of service and possible SSRF when using prerendering

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability results in a DoS whe…

πŸ“… Published: Jan. 15, 2026, 6:33 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:37 p.m.

8.4

CVSS4.0

CVE-2025-13845 -

CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.

πŸ“… Published: Jan. 15, 2026, 6:33 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.4

CVSS4.0

CVE-2025-13844 -

CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.

πŸ“… Published: Jan. 15, 2026, 6:28 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

7.1

CVSS3.1

CVE-2025-36911 -

In key-based pairing, there is a possible ID due to a logic error in the code. This could lead to remote (proximal/adjacent) information disclosure of user's conversations and location with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Jan. 15, 2026, 5:41 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 9:52 p.m.

6.3

CVSS4.0

CVE-2025-9014 - Null Pointer Dereference Vulnerability on TL-WR841N

A Null Pointer Dereference vulnerability exists in the referer header check of theΒ web portal of TP-Link TL-WR841N v14, caused by improper input validation.Β  A remote, unauthenticated attacker can exploit this flaw andΒ cause Denial of Service on the web portal service.This issue affects TL-WR841N v…

πŸ“… Published: Jan. 15, 2026, 5:36 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

4.3

CVSS3.1

CVE-2026-23494 - Pimcore is Missing Function Level Authorization on "Static Routes" Listing

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listing static routes. In Pimcore, static routes are custom URL patterns defined via …

πŸ“… Published: Jan. 15, 2026, 4:52 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 9:47 p.m.
Total resulsts: 329626
Page 173 of 32,963
Β« previous page Β» next page
Filters