10

CVSS4.0

CVE-2026-22240 - Plaintext Passwords Vulnerability in BLUVOYIX

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to retrieve the plaint…

📅 Published: Jan. 14, 2026, 2:42 p.m. 🔄 Last Modified: April 18, 2026, 4:30 p.m.

10

CVSS4.0

CVE-2026-22239 - Email Sending Vulnerability in BLUVOYIX

The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attack…

📅 Published: Jan. 14, 2026, 2:40 p.m. 🔄 Last Modified: April 18, 2026, 4:30 p.m.

10

CVSS4.0

CVE-2026-22238 - Administrator Account Creation Vulnerability in BLUVOYIX

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to create a new user with admin privileges. Successful exploitat…

📅 Published: Jan. 14, 2026, 2:38 p.m. 🔄 Last Modified: April 18, 2026, 6:30 a.m.

10

CVSS4.0

CVE-2026-22237 - Exposed Internal API Documentation Vulnerability in BLUVOYIX

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the APIs exposed by the documentation. Successful exploitation of this vulnerability co…

📅 Published: Jan. 14, 2026, 2:36 p.m. 🔄 Last Modified: April 18, 2026, 6:30 a.m.

10

CVSS4.0

CVE-2026-22236 - Improper Authentication Vulnerability in BLUVOYIX

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable APIs. Successful exploitation of this vulnerability could allow the atta…

📅 Published: Jan. 14, 2026, 2:34 p.m. 🔄 Last Modified: April 18, 2026, 6:30 a.m.

7.5

CVSS3.1

CVE-2025-9142 - Local privilege escalation in Harmony SASE Windows Agent

A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory.

📅 Published: Jan. 14, 2026, 2:30 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-14317 - User Enumeration in Crazy Bubble Tea mobile application

In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enumerating a `loyaltyGuestId` parameter. Server does not verify the permissions required to obtain the data. This issue was fixed in version 915 (Android) and 7.4.1 (iOS).

📅 Published: Jan. 14, 2026, 1:28 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-13175 - Insecure Password Storage in Y Soft SafeQ 6

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 …

📅 Published: Jan. 14, 2026, 12:19 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-14338 - Polkit authentication dis isabled by default in inputplumber

Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005.

📅 Published: Jan. 14, 2026, 11:55 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2025-66005 - Lack of Authentication in the InputManager D-Bus interface

Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session.

📅 Published: Jan. 14, 2026, 11:53 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345363
Page 1750 of 34,537
« previous page » next page
Filters