7.5

CVSS4.0

CVE-2025-68954 - Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. This allows a user that was already connected to SF…

πŸ“… Published: Jan. 6, 2026, 12:31 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 9:29 p.m.

9.8

CVSS3.1

CVE-2025-15444 - Crypt::Sodium::XS module versions prior toΒ 0.000042,Β for Perl, include a vulnerable version of libs…

Crypt::Sodium::XS module versions prior toΒ 0.000042,Β for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277Β  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The lib…

πŸ“… Published: Jan. 6, 2026, 12:22 a.m. πŸ”„ Last Modified: March 10, 2026, 5 p.m.

7.5

CVSS3.1

CVE-2026-21507 - iccDEV is Vulnerable to Denial of Service via Infinite Loop in CalcProfileID()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have an infinite loop in the IccProfile.cpp function, CalcProfileID. This issue is fixed in version 2.3.1.1.

πŸ“… Published: Jan. 6, 2026, 12:11 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 9:04 p.m.

7.5

CVSS3.1

CVE-2025-59379 -

DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information from the underlying SQL database via Blind SQL Injection through the user parameter in the login page. This allows an attacker to steal credentials, which may be cleartext, from ex…

πŸ“… Published: Jan. 6, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:41 a.m.

9.8

CVSS3.1

CVE-2025-60534 -

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.

πŸ“… Published: Jan. 6, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:24 a.m.

9.8

CVSS3.1

CVE-2025-60262 -

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attac…

πŸ“… Published: Jan. 6, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:36 a.m.

9.8

CVSS3.1

CVE-2025-65212 -

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into the d…

πŸ“… Published: Jan. 6, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:31 a.m.

2

CVSS4.0

CVE-2026-21439 - badkeys vulnerable to ASCII control character injection on console via malformed input

badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and below, an attacker may inject content with ASCII control characters like vertical tabs, ANSI escape sequences, etc., that can create misleading output of the badkeys command-line t…

πŸ“… Published: Jan. 5, 2026, 11:51 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:18 p.m.

2.7

CVSS4.0

CVE-2025-69230 - AIOHTTP Vulnerable to Cookie Parser Warning Storm

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application, then an attacker may be able to trigger a storm of warning-level logs u…

πŸ“… Published: Jan. 5, 2026, 11:47 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:17 p.m.

6.6

CVSS4.0

CVE-2025-69229 - AIOHTTP vulnerable to DoS through chunked messages

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an application makes use of the request.read() method in an endpoint, it …

πŸ“… Published: Jan. 5, 2026, 11:37 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 6:55 p.m.
Total resulsts: 344154
Page 1780 of 34,416
Β« previous page Β» next page
Filters