4.3

CVSS3.1

CVE-2026-24003 - EvseV2G has sequence state validation bypass

EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one, thereby updating the current context with illegiโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 10:12 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3 p.m.

6.7

CVSS4.0

CVE-2026-24131 - pnpm has Path Traversal via arbitrary file permission modification

pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package direโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 10:03 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:45 a.m.

5.1

CVSS4.0

CVE-2026-1445 - iJason-Liu Books_Manager upload_bookCover.php unrestricted upload

A vulnerability was found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This vulnerability affects unknown code of the file controllers/books_center/upload_bookCover.php. Performing a manipulation of the argument book_cover results in unrestricted upload. The attack maโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 10:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3 p.m.

6.7

CVSS4.0

CVE-2026-24056 - pnpm has symlink traversal in file:/git dependencies

pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package containing a symlink to an absolute path (e.g., `/etc/passwd`, `โ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 9:59 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:45 a.m.

6.5

CVSS3.1

CVE-2026-23890 - pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validation, and after scope normalization, path traversalโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 9:53 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:45 a.m.

6.5

CVSS3.1

CVE-2026-23889 - pnpm has Windows-specific tarball Path Traversal

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `.\`. On Windows, backslashes are directory separatโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 9:50 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3 p.m.

7.2

CVSS3.1

CVE-2025-59473 -

SQL Injection vulnerability in the Structure for Admin authenticated user

๐Ÿ“… Published: Jan. 26, 2026, 9:43 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 2:22 p.m.

5.9

CVSS3.1

CVE-2025-59471 - next: NextJS Denial of Service in Image Optimizer

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cauโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 9:43 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 3:03 p.m.

5.9

CVSS3.1

CVE-2025-59472 - next: NextJS Denial of Service in Partial Pre Rendering

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely relatโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 9:43 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:24 p.m.

6.5

CVSS3.1

CVE-2026-23888 - pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../` or absolute paths thaโ€ฆ

๐Ÿ“… Published: Jan. 26, 2026, 9:37 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:45 a.m.
Total resulsts: 349182
Page 1943 of 34,919
ยซ previous page ยป next page
Filters