6.5

CVSS3.1

CVE-2026-22773 - vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions

vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimensi…

📅 Published: Jan. 10, 2026, 6:39 a.m. 🔄 Last Modified: Jan. 10, 2026, 6:39 a.m.

4.3

CVSS3.1

CVE-2025-14943 - Blog2Social: Social Media Auto Post & Scheduler <= 8.7.2 - Incorrect Authorization to Authenticated…

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.7.2. This is due to a misconfigured authorization check on the 'getShipItemFullText' function which only verifies that a user has the 'rea…

📅 Published: Jan. 10, 2026, 6:32 a.m. 🔄 Last Modified: Jan. 10, 2026, 6:32 a.m.

8.1

CVSS3.1

CVE-2026-22704 - haxcms-php 11.0.6 Stored XSS Leading to Account Takeover

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vulnerable to stored XSS, which could lead to account takeover. This issue has been patched in version 25.0.0.

📅 Published: Jan. 10, 2026, 6:22 a.m. 🔄 Last Modified: Jan. 10, 2026, 6:23 a.m.

6.4

CVSS3.1

CVE-2026-22705 - RustCrypto: Signatures has timing side-channel in ML-DSA decomposition

RustCrypto: Signatures offers support for digital signatures, which provide authentication of data using public-key cryptography. Prior to version 0.1.0-rc.2, a timing side-channel was discovered in the Decompose algorithm which is used during ML-DSA signing to generate hints for the signature. Thi…

📅 Published: Jan. 10, 2026, 6:14 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:43 p.m.

5.5

CVSS3.1

CVE-2026-22703 - Cosign verification accepts any valid Rekor entry under certain conditions

Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key. When verifying a Rekor en…

📅 Published: Jan. 10, 2026, 6:11 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:43 p.m.

4.5

CVSS3.1

CVE-2026-22702 - virtualenv Has TOCTOU Vulnerabilities in Directory Creation

virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation operations. An attacker with local access can exploit a rac…

📅 Published: Jan. 10, 2026, 6:05 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:44 p.m.

5.3

CVSS3.1

CVE-2026-22701 - filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between …

📅 Published: Jan. 10, 2026, 5:59 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:45 p.m.

5.3

CVSS3.1

CVE-2026-22693 - Null Pointer Dereference in SubtableUnicodesCache::create leading to DoS

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at th…

📅 Published: Jan. 10, 2026, 5:53 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:47 p.m.

6.5

CVSS3.1

CVE-2026-22689 - Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to …

Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit WebSocket server is configured to accept connections from any origin. This lack of Origin header validation introduces a Cross-Site WebSocket Hijacking (CSWSH) vulnerability. An attacker can host a malicio…

📅 Published: Jan. 10, 2026, 5:46 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:47 p.m.

8.8

CVSS3.1

CVE-2026-22685 - DevToys Path Traversal (“Zip Slip”) Vulnerability in DevToys Extension Installation

DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension installation mechanism. When processing extension packages (NUPKG archives), DevToys does not sufficiently validate file paths contained within the arc…

📅 Published: Jan. 10, 2026, 5:43 a.m. 🔄 Last Modified: Jan. 10, 2026, 5:43 a.m.
Total resulsts: 327160
Page 19 of 32,716
« previous page » next page
Filters