9.3

CVSS4.0

CVE-2026-24479 - HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE

HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize filenames within uploaded ZIP archives. Attackers can craft a malicious ZIP file co…

πŸ“… Published: Jan. 27, 2026, 12:43 a.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

8.1

CVSS3.1

CVE-2026-24490 - MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The …

πŸ“… Published: Jan. 27, 2026, 12:40 a.m. πŸ”„ Last Modified: April 18, 2026, 3 p.m.

5.3

CVSS3.1

CVE-2026-24489 - Gakido vulnerable to HTTP Header Injection (CRLF Injection)

Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in Gakido prior to version 0.1.1 that allowed HTTP header injection through CRLF (Carriage Return Line Feed) sequences in user-supplied header values and names. When making HTTP requ…

πŸ“… Published: Jan. 27, 2026, 12:36 a.m. πŸ”„ Last Modified: April 18, 2026, 3 p.m.

8.6

CVSS3.1

CVE-2026-24486 - Python-Multipart has Arbitrary File Write via Non-Default Configuration

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by cra…

πŸ“… Published: Jan. 27, 2026, 12:34 a.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

8.7

CVSS4.0

CVE-2026-24480 - QGIS had validated RCE and Repository Takeover via GitHub Actions

QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actions workflow called "pre-commit checks" that, before commit 76a693cd91650f9b4e83edac525e5e4f90d954e9, was vulnerable to remote code execution and repository compromise because it u…

πŸ“… Published: Jan. 27, 2026, 12:32 a.m. πŸ”„ Last Modified: April 18, 2026, 7 p.m.

4.3

CVSS3.1

CVE-2026-23683 - Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation)

SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has low impact on confidentiality, integrity and availability are not impacted.

πŸ“… Published: Jan. 27, 2026, 12:22 a.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

9.8

CVSS3.1

CVE-2025-69563 -

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.

πŸ“… Published: Jan. 27, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 2:01 p.m.

7.5

CVSS3.1

CVE-2025-69420 - Missing ASN1_TYPE validation in TS_RESP_verify_response() function

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed TimeStamp Response file. Impact summary: An app…

πŸ“… Published: Jan. 27, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 6:33 p.m.

5.5

CVSS3.1

CVE-2025-28162 - libpng: libpng: Denial of Service via buffer overflow in pngimage utility

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

πŸ“… Published: Jan. 27, 2026, midnight πŸ”„ Last Modified: Feb. 6, 2026, 8:06 p.m.

6.1

CVSS3.1

CVE-2025-11187 - Improper validation of PBMAC1 parameters in PKCS#12 MAC verification

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial o…

πŸ“… Published: Jan. 27, 2026, midnight πŸ”„ Last Modified: March 20, 2026, 2:16 p.m.
Total resulsts: 349182
Page 1939 of 34,919
Β« previous page Β» next page
Filters