9.8

CVSS3.1

CVE-2026-24061 -

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

πŸ“… Published: Jan. 21, 2026, 6:42 a.m. πŸ”„ Last Modified: April 22, 2026, 4 a.m.

7.4

CVSS3.1

CVE-2025-68133 - EVerest's unlimited connections can lead to DoS through operating system resource exhaustion

EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module to terminate by initiating an unlimited number of TCP connections that never proceed to ISO 15118-2 communication. This is possible because a new thre…

πŸ“… Published: Jan. 21, 2026, 2:25 a.m. πŸ”„ Last Modified: Feb. 6, 2026, 9:21 p.m.

9.8

CVSS3.1

CVE-2025-15521 - Academy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privi…

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their password an…

πŸ“… Published: Jan. 21, 2026, 1:23 a.m. πŸ”„ Last Modified: April 22, 2026, midnight

6.5

CVSS3.1

CVE-2025-14559 - Org.keycloak/keycloak-services: keycloak keycloak-services: business logic flaw allows unauthorized…

A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privi…

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-66959 - ollama: ollama: Denial of Service via GGUF decoder

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 5:27 p.m.

7.5

CVSS3.1

CVE-2025-70646 -

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 9 p.m.

9.8

CVSS3.1

CVE-2025-69766 -

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 8:38 p.m.

7.5

CVSS3.1

CVE-2025-66960 - ollama: ollama: Denial of Service via untrusted GGUF metadata string length

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 5:27 p.m.

3.1

CVSS3.1

CVE-2026-1035 - Org.keycloak.protocol.oidc: keycloak refresh token reuse bypass via toctou race condition

A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This …

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 8 a.m.

7.5

CVSS3.1

CVE-2025-70645 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilterCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 21, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 8:52 p.m.
Total resulsts: 346094
Page 1737 of 34,610
Β« previous page Β» next page
Filters