9.1

CVSS3.1

CVE-2025-57794 - Unrestricted File Upload Vulnerability in Explorance Blue

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remo…

πŸ“… Published: Jan. 28, 2026, 5:33 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 4:59 p.m.

10

CVSS3.1

CVE-2025-57792 - SQL Injection Vulnerability in Explorance Blue

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part of backend database queries. The issue is exploitable without authentication, s…

πŸ“… Published: Jan. 28, 2026, 5:26 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 5:01 p.m.

5.5

CVSS3.1

CVE-2025-46306 - Bounds Check Failure in Keynote Allows Memory Disclosure

The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafted Keynote file may disclose memory contents.

πŸ“… Published: Jan. 28, 2026, 5:26 p.m. πŸ”„ Last Modified: April 22, 2026, 8:15 p.m.

4.3

CVSS3.1

CVE-2025-46316 - Out‑of‑Bounds Read in Apple Pages and Apple OS Leading to Application Crash or Memory Disclosure

An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.

πŸ“… Published: Jan. 28, 2026, 5:26 p.m. πŸ”„ Last Modified: April 27, 2026, 9:15 p.m.

8.6

CVSS3.1

CVE-2025-57793 - SQL Injection Vulnerability in Explorance Blue

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly e…

πŸ“… Published: Jan. 28, 2026, 5:09 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 5 p.m.

9.4

CVSS4.0

CVE-2026-24685 - OpenProject has Argument Injection on Repository module that allows Arbitrary File Write

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitrary file write vulnerability in OpenProject’s repository diff download endpoint (`/projects/:project_id/repository/diff.diff`) when rendering a single revision via git show. By su…

πŸ“… Published: Jan. 28, 2026, 4:47 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 p.m.

4.4

CVSS3.1

CVE-2025-13919 - Component Object Model (COM) Hijacking in Symantec Endpoint Protection Windows Client

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a COM Hijacking vulnerability, which is a type of issue whereby an attacker attempts to establish persistence and evade detection by hijacking COM references in the Windows Registry.

πŸ“… Published: Jan. 28, 2026, 4:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-13918 - Elevation of Privileges in Symantec Endpoint Protection Windows Client

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normall…

πŸ“… Published: Jan. 28, 2026, 4:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-1522 - Open5GS SGWC s5c-handler.c sgwc_s5c_handle_modify_bearer_response denial of service

A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_bearer_response of the file src/sgwc/s5c-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit ha…

πŸ“… Published: Jan. 28, 2026, 4:32 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 p.m.

7

CVSS3.1

CVE-2025-13917 - Elevation of Privileges in Web Security Services (WSS) Agent

WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

πŸ“… Published: Jan. 28, 2026, 4:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1909 of 34,919
Β« previous page Β» next page
Filters