2.7

CVSS4.0

CVE-2026-22690 - pypdf has possible long runtimes for missing /Root object with large /Size values

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for actually invalid files. This can be a…

📅 Published: Jan. 10, 2026, 4:41 a.m. 🔄 Last Modified: Jan. 22, 2026, 3:35 p.m.

10

CVSS3.1

CVE-2026-22688 - WeKnora has Command Injection in MCP stdio test

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subproce…

📅 Published: Jan. 10, 2026, 3:41 a.m. 🔄 Last Modified: Jan. 22, 2026, 2:39 p.m.

5.6

CVSS3.1

CVE-2026-22687 - WeKnora vulnerable to SQL Injection

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass tech…

📅 Published: Jan. 10, 2026, 3:41 a.m. 🔄 Last Modified: March 10, 2026, 6:34 p.m.

8.5

CVSS4.0

CVE-2026-22610 - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulne…

📅 Published: Jan. 10, 2026, 3:35 a.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.

7.5

CVSS3.1

CVE-2025-13457 - WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Informa…

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Sq…

📅 Published: Jan. 10, 2026, 3:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2026-22589 - Spree API has Unauthenticated IDOR - Guest Address

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supply…

📅 Published: Jan. 10, 2026, 3:17 a.m. 🔄 Last Modified: Jan. 22, 2026, 1:45 p.m.

6.1

CVSS3.1

CVE-2025-61674 - October CMS Vulnerable to Stored XSS via Editor and Branding Styles

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permission could inject malicious HTML/JS into the stylesh…

📅 Published: Jan. 10, 2026, 3:14 a.m. 🔄 Last Modified: Jan. 20, 2026, 4:06 p.m.

6.1

CVSS3.1

CVE-2025-61676 - October CMS Vulnerable to Stored XSS via Branding Styles

October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the sty…

📅 Published: Jan. 10, 2026, 3:14 a.m. 🔄 Last Modified: Jan. 20, 2026, 4:05 p.m.

10

CVSS3.1

CVE-2025-65091 - XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been pat…

📅 Published: Jan. 10, 2026, 3:06 a.m. 🔄 Last Modified: Jan. 29, 2026, 5:27 p.m.

5.3

CVSS3.1

CVE-2025-65090 - XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of passwords. This issue has b…

📅 Published: Jan. 10, 2026, 3:05 a.m. 🔄 Last Modified: Jan. 29, 2026, 5:27 p.m.
Total resulsts: 344826
Page 1769 of 34,483
« previous page » next page
Filters