7.2

CVSS4.0

CVE-2026-22708 - Cursor has a Terminal Tool Allowlist Bypass via Environment Variables

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indire…

πŸ“… Published: Jan. 14, 2026, 4:43 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.1

CVSS3.1

CVE-2026-22694 - AliasVault is Missing Origin Validation in Android Passkey Credential Provider

AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for …

πŸ“… Published: Jan. 14, 2026, 4:32 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

2.3

CVSS4.0

CVE-2026-21889 - Weblate leaks information via screenshots

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

πŸ“… Published: Jan. 14, 2026, 4:28 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

7.2

CVSS3.1

CVE-2025-37181 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading …

πŸ“… Published: Jan. 14, 2026, 4:26 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:17 p.m.

5.5

CVSS3.1

CVE-2025-37185 - Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator …

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary …

πŸ“… Published: Jan. 14, 2026, 4:20 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:14 p.m.

9.8

CVSS3.1

CVE-2025-37184 - Unauthenticated Bypass Allows Multi-Factor Authentication Circumvention

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compro…

πŸ“… Published: Jan. 14, 2026, 4:19 p.m. πŸ”„ Last Modified: March 3, 2026, 6:16 p.m.

7.2

CVSS3.1

CVE-2025-37183 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading …

πŸ“… Published: Jan. 14, 2026, 4:18 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:17 p.m.

7.2

CVSS3.1

CVE-2025-37182 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading …

πŸ“… Published: Jan. 14, 2026, 4:17 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:17 p.m.

5.1

CVSS4.0

CVE-2026-22211 - TinyOS <= 2.1.2 Global Buffer Overflow in printfUART

TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 networking stack. The implementation formats output into a fixed-size global buffer and concatenates strings for %s forma…

πŸ“… Published: Jan. 14, 2026, 3:19 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

6.3

CVSS4.0

CVE-2026-22820 - Outray cli is vulnerable to race conditions in tunnels creation

Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.

πŸ“… Published: Jan. 14, 2026, 3:06 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.
Total resulsts: 345363
Page 1749 of 34,537
Β« previous page Β» next page
Filters