7.5

CVSS3.1

CVE-2024-48077 -

NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapid exhaustion of system file descriptors (FDs). This exhaustion triggers a process crash, rendering the broker unable to…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 4:16 p.m.

7.5

CVSS3.1

CVE-2025-70307 -

A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 5:58 p.m.

7.5

CVSS3.1

CVE-2025-67076 -

Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read files on the system via the misc controller and the ExternalGetFile action. Only files with an extension can be read.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 2:45 p.m.

7.5

CVSS3.1

CVE-2025-70656 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 20, 2026, 5:34 p.m.

3.7

CVSS3.1

CVE-2026-0976 - Org.keycloak/keycloak-quarkus-server: keycloak: proxy bypass due to improper handling of matrix par…

A flaw was found in Keycloak. This improper input validation vulnerability occurs because Keycloak accepts RFC-compliant matrix parameters in URL path segments, while common reverse proxy configurations may ignore or mishandle them. A remote attacker can craft requests to mask path segments, potent…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7:15 p.m.

9.9

CVSS3.1

CVE-2025-67084 -

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 4:03 p.m.

9.8

CVSS3.1

CVE-2025-67079 -

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 2:42 p.m.

6.2

CVSS4.0

CVE-2026-0600 - Nexus Repository 3 - Server-Side Request Forgery in Proxy Repository Configuration

Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenticated administrators to configure proxy repositories with URLs that can access unintended network destinations, potentially including cloud metadata services and internal network …

πŸ“… Published: Jan. 14, 2026, 10:29 p.m. πŸ”„ Last Modified: April 18, 2026, 6:15 a.m.

7.5

CVSS3.1

CVE-2025-12166 - Simply Schedule Appointments <= 1.6.9.9 - Unauthenticated SQL Injection via `order` and `append_whe…

The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection via the `order` and `append_where_sql` parameters in all versions up to, and including, 1.6.9.9 due to insufficient escaping on the user supplied parameter and la…

πŸ“… Published: Jan. 14, 2026, 10:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.4

CVSS4.0

CVE-2025-14058 -

A potential missing authentication vulnerability was reported in some Lenovo Tablets that could allow an unauthorized user with physical access to modify Control Center settings if the device is locked when the "Allow Control Center access when locked" option is disabled.

πŸ“… Published: Jan. 14, 2026, 10:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345359
Page 1744 of 34,536
Β« previous page Β» next page
Filters