5.3

CVSS4.0

CVE-2025-15265 - Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a <script> block without HTML‑safe escaping, allowing </script> to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, w…

📅 Published: Jan. 15, 2026, 7:59 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:04 p.m.

9.3

CVSS4.0

CVE-2026-23746 - Entrust Instant Financial Issuance (IFI) SmartCardController Service .NET Remoting RCE

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoti…

📅 Published: Jan. 15, 2026, 7:44 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

7.4

CVSS4.0

CVE-2026-23622 - CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover

Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters fro…

📅 Published: Jan. 15, 2026, 7:28 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

8.9

CVSS3.1

CVE-2026-23527 - Request Smuggling (TE.TE) in h3 v1

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this heade…

📅 Published: Jan. 15, 2026, 7:24 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:50 p.m.

9.1

CVSS3.1

CVE-2026-23520 - Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run…

📅 Published: Jan. 15, 2026, 7:20 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

4.1

CVSS3.1

CVE-2026-23766 - istio: From CVEorg collector

Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."

📅 Published: Jan. 15, 2026, 7:18 p.m. 🔄 Last Modified: Jan. 16, 2026, 3:55 p.m.

8.9

CVSS4.0

CVE-2026-23519 - RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (…

📅 Published: Jan. 15, 2026, 7:13 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:59 p.m.

5.3

CVSS3.1

CVE-2026-23511 - ZITADEL has a user enumeration vulnerability in Login UIs

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and …

📅 Published: Jan. 15, 2026, 7:09 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:44 p.m.

7.5

CVSS3.1

CVE-2026-22775 - devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

📅 Published: Jan. 15, 2026, 6:59 p.m. 🔄 Last Modified: Jan. 20, 2026, 3:29 p.m.

7.5

CVSS3.1

CVE-2026-22774 - devalue vulnerable to denial of service due to memory exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

📅 Published: Jan. 15, 2026, 6:53 p.m. 🔄 Last Modified: Jan. 20, 2026, 3:28 p.m.
Total resulsts: 329712
Page 178 of 32,972
« previous page » next page
Filters