6.5

CVSS3.1

CVE-2025-36427 - IBM Db2 Denial of Service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a user to cause a denial of service due to insufficient validation of special elements in data query logic.

πŸ“… Published: Jan. 30, 2026, 9:27 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 8:57 p.m.

5.3

CVSS3.1

CVE-2025-36428 - IBM Db2 Denial of Service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when the RPSCAN feature is enabled.

πŸ“… Published: Jan. 30, 2026, 9:27 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 7:39 p.m.

6.5

CVSS3.1

CVE-2025-36442 - IBM Db2 Denial of Service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as the server may crash under certain conditions with a specially crafted query with XML columns.

πŸ“… Published: Jan. 30, 2026, 9:18 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 7:39 p.m.

9.2

CVSS4.0

CVE-2026-1723 - TOTOLINK X6000R Unauthenticated Command Injection Vulnerability

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.

πŸ“… Published: Jan. 30, 2026, 8:52 p.m. πŸ”„ Last Modified: April 18, 2026, 1:15 a.m.

9.3

CVSS4.0

CVE-2026-25141 - Orval has a code injection via unsanitized x-enum-descriptions uing JS comments

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('), double quotes (") and…

πŸ“… Published: Jan. 30, 2026, 8:19 p.m. πŸ”„ Last Modified: April 18, 2026, 1:15 a.m.

9.7

CVSS3.1

CVE-2026-25130 - Cybersecurity AI vulnerable to command Injection through argument injection in find_file Agent tool

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via `subprocess.Popen()` with `s…

πŸ“… Published: Jan. 30, 2026, 8:15 p.m. πŸ”„ Last Modified: April 18, 2026, 1:15 a.m.

6.7

CVSS3.1

CVE-2026-25129 - PsySH has Local Privilege Escalation via CWD .psysh.php auto-load

PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as th…

πŸ“… Published: Jan. 30, 2026, 8:12 p.m. πŸ”„ Last Modified: April 18, 2026, 1:15 a.m.

9.2

CVSS4.0

CVE-2025-24293 - activestorage: Code injection in Active Storage when used in conjunction with the image_processing …

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which …

πŸ“… Published: Jan. 30, 2026, 8:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS4.0

CVE-2026-23835 - LobeHub Vulnerable to Improper Authorization in Presigned Upload

LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the request parameters. As a result, it is possible to create arbit…

πŸ“… Published: Jan. 30, 2026, 8:04 p.m. πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

8.8

CVSS4.0

CVE-2025-11175 - DiscussionTools should use better regex

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki - DiscussionTools Extensio…

πŸ“… Published: Jan. 30, 2026, 7:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1881 of 34,919
Β« previous page Β» next page
Filters