3.1

CVSS3.1

CVE-2025-53470 - Apache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver

Out-of-bounds Read vulnerability in Apache NimBLE HCI H4 driver. Specially crafted HCI event could lead to invalid memory read in H4 driver. This issue affects Apache NimBLE: through 1.8.  This issue requires a broken or bogus Bluetooth controller and thus severity is considered low. Users are …

📅 Published: Jan. 10, 2026, 9:46 a.m. 🔄 Last Modified: Jan. 14, 2026, 5:38 p.m.

7.5

CVSS3.1

CVE-2025-53477 - Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer

NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus severity is considered low. This issue aff…

📅 Published: Jan. 10, 2026, 9:45 a.m. 🔄 Last Modified: Jan. 14, 2026, 5:38 p.m.

8.1

CVSS3.1

CVE-2025-62235 - Apache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairing

Authentication Bypass by Spoofing vulnerability in Apache NimBLE. Receiving specially crafted Security Request could lead to removal of original bond and re-bond with impostor. This issue affects Apache NimBLE: through 1.8.0. Users are recommended to upgrade to version 1.9.0, which fixes the issu…

📅 Published: Jan. 10, 2026, 9:42 a.m. 🔄 Last Modified: Jan. 14, 2026, 5:45 p.m.

5.3

CVSS3.1

CVE-2026-0831 - Templately <= 3.4.8 - Unauthenticated Limited Arbitrary JSON File Write

The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the `save_template_to_file()` function where user-controlled parameters like `session_id`, `content_id`, and `ai_page_ids` are used to…

📅 Published: Jan. 10, 2026, 9:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15503 - Sangfor Operation and Maintenance Management System common.jsp unrestricted upload

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possibl…

📅 Published: Jan. 10, 2026, 9:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:27 a.m.

5.4

CVSS3.1

CVE-2025-14976 - User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce val…

📅 Published: Jan. 10, 2026, 8:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-15502 - Sangfor Operation and Maintenance Management System session SessionController os command injection

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be execute…

📅 Published: Jan. 10, 2026, 8:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:27 a.m.

5.3

CVSS3.1

CVE-2025-14948 - miniOrange OTP Verification and SMS Notification for WooCommerce <= 4.3.8 - Missing Authorization t…

The miniOrange OTP Verification and SMS Notification for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `enable_wc_sms_notification` AJAX action in all versions up to, and including, 4.3.8. This makes it possible for unau…

📅 Published: Jan. 10, 2026, 7:03 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2026-22777 - ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler

ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an attacker can inject special characters into HTTP query parameters to add arbitrary configuration values to the config.ini file. This can lead to security setting tampering or modific…

📅 Published: Jan. 10, 2026, 6:43 a.m. 🔄 Last Modified: Feb. 5, 2026, 9:02 p.m.

6.5

CVSS3.1

CVE-2026-22773 - vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimensi…

📅 Published: Jan. 10, 2026, 6:39 a.m. 🔄 Last Modified: Jan. 27, 2026, 9:03 p.m.
Total resulsts: 344840
Page 1768 of 34,484
« previous page » next page
Filters