6.5

CVSS3.1

CVE-2026-21885 - Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources

Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen medโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 1:57 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 4:55 p.m.

9.3

CVSS3.1

CVE-2026-21876 - OWASP CRS has multipart bypass using multiple content-type parts

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a coโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 1:55 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 4:16 p.m.

5.9

CVSS4.0

CVE-2025-8307 - Recoverable passwords in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embeddโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 1:43 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

5.1

CVSS4.0

CVE-2025-8306 - Improper Access Control in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due to lack of granularity in access control.ย  Chained exploitaโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 1:43 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

7.5

CVSS3.1

CVE-2025-69260 -

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.

๐Ÿ“… Published: Jan. 8, 2026, 12:50 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 7:11 p.m.

7.5

CVSS3.1

CVE-2025-69259 -

A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability..

๐Ÿ“… Published: Jan. 8, 2026, 12:50 p.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 7:14 p.m.

9.8

CVSS3.1

CVE-2025-69258 -

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

๐Ÿ“… Published: Jan. 8, 2026, 12:50 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

9.8

CVSS3.1

CVE-2025-62877 - Harvest may expose OS default ssh login password via SUSE Virtualization Interactive Installer

Projects using the SUSE Virtualization (Harvester) environment mayย expose the OS default ssh login passwordย ย if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism โ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, 12:29 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

8.8

CVSS3.1

CVE-2025-66001 - NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)

NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote server's authenticity and integrity) for OpenID Connect is not enforced by default. As a result this may expose the system to man-in-the-middle (MITM) attacks.

๐Ÿ“… Published: Jan. 8, 2026, 10:23 a.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

8.5

CVSS3.1

CVE-2025-14459 - Virt-cdi-controller: unauthorized pvc cloning via dataimportcron

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.

๐Ÿ“… Published: Jan. 8, 2026, 10:10 a.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 2:59 p.m.
Total resulsts: 344676
Page 1777 of 34,468
ยซ previous page ยป next page
Filters