8.2

CVSS3.1

CVE-2026-22788 - WebErpMesv2 allows unauthenticated API Access

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote attacker can read business-critical data including companies, qu…

πŸ“… Published: Jan. 12, 2026, 9:40 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 7:11 p.m.

9.3

CVSS4.0

CVE-2025-12420 - Unauthenticated Privilege Escalation in ServiceNow AI Platform

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update …

πŸ“… Published: Jan. 12, 2026, 9:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

7.3

CVSS4.0

CVE-2026-22786 - Gin-vue-admin has arbitrary file upload vulnerability caused by path traversal

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint resume upload functionality. Attacker can upload any files on any directory. In the breakpoint_continue.go file, the MakeFile function accepts a fileName…

πŸ“… Published: Jan. 12, 2026, 9:09 p.m. πŸ”„ Last Modified: March 12, 2026, 7:04 p.m.

5.8

CVSS3.1

CVE-2026-22772 - Fulcio vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF …

πŸ“… Published: Jan. 12, 2026, 8:58 p.m. πŸ”„ Last Modified: March 5, 2026, 1:48 p.m.

0.0

CVE-2026-0866 -

After the publication of the PoC by the researcher and further analysis, we have determined that this issue does not constitute a valid vulnerability. The technique described is an obfuscation method and does not bypass or impact any implicit or explicit security controls.

πŸ“… Published: Jan. 12, 2026, 7:26 p.m. πŸ”„ Last Modified: March 18, 2026, 8:16 p.m.

9.3

CVSS4.0

CVE-2026-22785 - orval MCP client is vulnerable to a code injection attack.

orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation logic relies on string manipulation that incorporates the summary field from the OpenAPI specification without proper validation or escaping. This allo…

πŸ“… Published: Jan. 12, 2026, 6:43 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 8 p.m.

2.3

CVSS4.0

CVE-2026-22784 - Lychee cross-album password propagation on Album unlocking

Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's album password unlock functionality that allows users to gain possibly unauthorized access to other users' password-protected albums. When a user unlocks a password-protected publi…

πŸ“… Published: Jan. 12, 2026, 6:37 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 6:39 p.m.

8.7

CVSS4.0

CVE-2026-22200 - osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read

Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently …

πŸ“… Published: Jan. 12, 2026, 6:34 p.m. πŸ”„ Last Modified: April 16, 2026, 8:45 a.m.

9.6

CVSS3.1

CVE-2026-22783 - Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in the delete operation …

πŸ“… Published: Jan. 12, 2026, 6:27 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 6:42 p.m.

10

CVSS4.0

CVE-2026-22781 - TinyWeb CGI Command Injection

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An un…

πŸ“… Published: Jan. 12, 2026, 6:23 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 6:44 p.m.
Total resulsts: 344980
Page 1772 of 34,498
Β« previous page Β» next page
Filters