7.3

CVSS4.0

CVE-2025-15545 - Insufficient Backup File Upload Input Validation on TP-Link Archer RE605X

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker…

πŸ“… Published: Jan. 29, 2026, 5:31 p.m. πŸ”„ Last Modified: March 9, 2026, 4:55 p.m.

6.8

CVSS4.0

CVE-2026-24413 - Icinga has insecure permission of %ProgramData%\icinga2\var on Windows

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the…

πŸ“… Published: Jan. 29, 2026, 5:21 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 p.m.

8.8

CVSS4.0

CVE-2026-24054 - Kata Containers Runtime: Host block device can be hotplugged to the VM if the container image is ma…

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter dir…

πŸ“… Published: Jan. 29, 2026, 5:16 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 a.m.

7.2

CVSS3.1

CVE-2026-23896 - immich API Key Privilege Escalation vulnerability

immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version 2.5.0 fixes the issue.

πŸ“… Published: Jan. 29, 2026, 5:12 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 a.m.

5.1

CVSS4.0

CVE-2026-1598 - Bdtask Bhojon All-In-One Restaurant Management System User Information profile cross site scripting

A vulnerability was found in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. Impacted is an unknown function of the file /dashboard/home/profile of the component User Information Module. Performing a manipulation of the argument fullname results in cross site scripting. It is …

πŸ“… Published: Jan. 29, 2026, 5:02 p.m. πŸ”„ Last Modified: April 18, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-1597 - Bdtask SalesERP Administrative Endpoint improper authorization

A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session leads to improper authorization. The attack may be performed from remote. The exploit has been disclose…

πŸ“… Published: Jan. 29, 2026, 4:32 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 p.m.

8.3

CVSS3.1

CVE-2025-62514 - `libparsec_crypto` does not check for weak order point of curve 25519

Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, `libparsec_crypto`, a component of the Parsec application, does not check for weak order point of Curve25519 when compiled with its RustCrypto backend. In practice this means…

πŸ“… Published: Jan. 29, 2026, 3:46 p.m. πŸ”„ Last Modified: March 2, 2026, 6:34 p.m.

5.3

CVSS4.0

CVE-2026-1596 - D-Link DWR-M961 formLtefotaUpgradeQuectel sub_419920 command injection

A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published a…

πŸ“… Published: Jan. 29, 2026, 3:32 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 a.m.

6.9

CVSS4.0

CVE-2026-1595 - itsourcecode Society Management System edit_student_query.php sql injection

A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

πŸ“… Published: Jan. 29, 2026, 3:32 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 p.m.

5.1

CVSS4.0

CVE-2026-0936 - Insertion of Sensitive Information into Logfile

An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential information which is processed by the PVI client application. The logging function of the PVI client application is disable…

πŸ“… Published: Jan. 29, 2026, 3:30 p.m. πŸ”„ Last Modified: April 18, 2026, 1:30 a.m.
Total resulsts: 349182
Page 1892 of 34,919
Β« previous page Β» next page
Filters