7.9

CVSS3.0

CVE-2026-21569 - Authenticated XXE in Atlassian Crowd allowing external entity access

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has h…

📅 Published: Jan. 28, 2026, 12:30 a.m. 🔄 Last Modified: April 18, 2026, 2 a.m.

6.1

CVSS3.1

CVE-2026-24852 - iccDEV has a heap-buffer-overflow in icXmlParseTextString()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, a heap buffer over-read when the strlen() function attempts to read a non-null-terminated buffer potentially leaking heap memory con…

📅 Published: Jan. 28, 2026, 12:27 a.m. 🔄 Last Modified: April 18, 2026, 2 a.m.

5.3

CVSS3.1

CVE-2026-24850 - ML-DSA Signature Verification Accepts Signatures with Repeated Hint Indices

The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to version 0.1.0-rc.4, the ML-DSA signature verification implementation in the RustCrypto `ml-dsa` crate incorrectly accepts signatures with repeated (dupli…

📅 Published: Jan. 28, 2026, 12:24 a.m. 🔄 Last Modified: April 18, 2026, 2 a.m.

8.2

CVSS3.1

CVE-2026-24842 - node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traver…

📅 Published: Jan. 28, 2026, 12:20 a.m. 🔄 Last Modified: April 18, 2026, 2:45 p.m.

9.9

CVSS3.1

CVE-2026-24841 - Dokploy Vulnerable to Authenticated Remote Code Execution via Command Injection in Docker Container…

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId` and `activeWay` parameters are directly interpolated into shell commands with…

📅 Published: Jan. 28, 2026, 12:18 a.m. 🔄 Last Modified: April 18, 2026, 2 a.m.

8

CVSS3.1

CVE-2026-24840 - Dokploy uses hardcoded credentials in installation script, which could result in database access

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in the provided installation script (located at https://dokploy.com/install.sh, line 154) uses a hardcoded password when creating the database container. This means that nearly all Dok…

📅 Published: Jan. 28, 2026, 12:15 a.m. 🔄 Last Modified: April 18, 2026, 2 a.m.

4.7

CVSS3.1

CVE-2026-24839 - Dokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headers

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, the Dokploy web interface is vulnerable to Clickjacking attacks due to missing frame-busting headers. This allows attackers to embed Dokploy pages in malicious iframes and trick authenticated users into perf…

📅 Published: Jan. 28, 2026, 12:01 a.m. 🔄 Last Modified: April 18, 2026, 8:45 p.m.

7.5

CVSS3.1

CVE-2025-71000 -

An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

📅 Published: Jan. 28, 2026, midnight 🔄 Last Modified: Feb. 3, 2026, 5:49 p.m.

6.5

CVSS3.1

CVE-2025-69601 -

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write file…

📅 Published: Jan. 28, 2026, midnight 🔄 Last Modified: Feb. 9, 2026, 5:25 p.m.

9.1

CVSS3.1

CVE-2025-69602 -

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can…

📅 Published: Jan. 28, 2026, midnight 🔄 Last Modified: Feb. 9, 2026, 5:24 p.m.
Total resulsts: 349182
Page 1918 of 34,919
« previous page » next page
Filters