7.5

CVSS3.1

CVE-2025-61726 - Memory exhaustion in query parameter parsing in net/url

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing…

πŸ“… Published: Jan. 28, 2026, 7:30 p.m. πŸ”„ Last Modified: Feb. 6, 2026, 6:47 p.m.

5.3

CVSS3.1

CVE-2025-61730 - Handshake messages may be processed at the incorrect encryption level in crypto/tls

During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensions messages), the subsequent messages may be processed before the encryption level changes. This can cause some minor information disclosu…

πŸ“… Published: Jan. 28, 2026, 7:30 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 8:36 p.m.

7.8

CVSS3.1

CVE-2025-61731 - Arbitrary file write using cgo pkg-config directive in cmd/go

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a "--log-f…

πŸ“… Published: Jan. 28, 2026, 7:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

7

CVSS3.1

CVE-2025-68119 - Unexpected code execution when invoking toolchain in cmd/go

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This i…

πŸ“… Published: Jan. 28, 2026, 7:30 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

7.1

CVSS4.0

CVE-2025-69218 - Discourse moderators can access admin-only reports exposing private upload URLs

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, moderators can access the `top_uploads` admin report which should be restricted to admins only. This report displays direct URLs to all uploaded files on the site, including sensitive co…

πŸ“… Published: Jan. 28, 2026, 7:30 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:47 p.m.

6.5

CVSS3.1

CVE-2025-68934 - Discourse Has Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60 seconds per request. This affects all users as t…

πŸ“… Published: Jan. 28, 2026, 7:19 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:47 p.m.

6.9

CVSS3.1

CVE-2025-68933 - Discourse non-admin moderators can exfiltrate private content via post ownership transfer

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, non-admin moderators with the `moderators_change_post_ownership` setting enabled can change ownership of posts in private messages and restricted categories they cannot access, then expo…

πŸ“… Published: Jan. 28, 2026, 7:17 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:47 p.m.

5.9

CVSS4.0

CVE-2025-68666 - Discourse users archives leaked to users with moderation privileges

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, users archives are viewable by users with moderation privileges even though moderators should not have access to the archives. Private topic/post content made by the users are leaked thr…

πŸ“… Published: Jan. 28, 2026, 7:14 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:58 p.m.

7.6

CVSS3.1

CVE-2025-68662 - FinalDestination hostname matching allows SSRF protection bypass

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1…

πŸ“… Published: Jan. 28, 2026, 7:12 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 8:44 p.m.

4.8

CVSS4.0

CVE-2026-0749 - Cross-Site Scripting Vulnerability in Drupal Form Builder Module

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22.

πŸ“… Published: Jan. 28, 2026, 6:56 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 p.m.
Total resulsts: 349182
Page 1905 of 34,919
Β« previous page Β» next page
Filters