6.1

CVSS3.0

CVE-2026-21642 - Reflected XSS in Revive Adserver Administrator Scripts

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML…

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 8 p.m.

6.1

CVSS3.0

CVE-2026-21664 - Reflected Cross‑Site Scripting in Revive Adserver afr.php Delivery Script

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent …

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 a.m.

6.1

CVSS3.0

CVE-2026-21663 - Reflected XSS in Revive Adserver Banner ACL

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser a…

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 7:15 p.m.

2.7

CVSS3.1

CVE-2026-21640 - Format String Injection in Revive Adserver Settings Causing Admin Console Crash

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 3:45 p.m.

6.5

CVSS3.1

CVE-2026-21641 - Authorization Bypass in Revive Adserver Tracker Deletion

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

7.5

CVSS3.1

CVE-2025-59465 - nodejs: Nodejs denial of service

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that …

πŸ“… Published: Jan. 20, 2026, 8:41 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:25 p.m.

10.0

CVSS3.1

CVE-2026-21636 - nodejs: Nodejs network segmentation bypass

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to arbitrary local sockets via net, tls, or undici/…

πŸ“… Published: Jan. 20, 2026, 8:41 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 a.m.

7.5

CVSS3.1

CVE-2026-21637 - nodejs: Nodejs denial of service

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immedi…

πŸ“… Published: Jan. 20, 2026, 8:41 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 a.m.

7.1

CVSS3.1

CVE-2025-55131 - nodejs: Nodejs uninitialized memory exposure

A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain le…

πŸ“… Published: Jan. 20, 2026, 8:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-59466 - nodejs: Nodejs denial of service

We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applications that rely on …

πŸ“… Published: Jan. 20, 2026, 8:41 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:25 p.m.
Total resulsts: 346099
Page 1746 of 34,610
Β« previous page Β» next page
Filters