4.8

CVSS4.0

CVE-2026-1444 - iJason-Liu Books_Manager add_book_check.php cross site scripting

A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects an unknown part of the file controllers/books_center/add_book_check.php. Such manipulation of the argument mark leads to cross site scripting. The attack can be launched remotely.…

πŸ“… Published: Jan. 26, 2026, 9:32 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 p.m.

9.8

CVSS3.1

CVE-2026-22709 - vm2 has a Sandbox Escape

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In lib/setup-sandbox.js, the callback function of `localPromise…

πŸ“… Published: Jan. 26, 2026, 9:32 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

9.3

CVSS4.0

CVE-2026-22696 - dcap-qvl has Missing Verification for QE Identity

dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 involves a critical gap in the cryptographic verification process within the dcap-qvl. The library fetches QE Identity collateral (including qe_identity…

πŸ“… Published: Jan. 26, 2026, 9:28 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

6.9

CVSS4.0

CVE-2026-1443 - code-projects Online Music Site AdminDeleteUser.php sql injection

A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and …

πŸ“… Published: Jan. 26, 2026, 8:02 p.m. πŸ”„ Last Modified: April 18, 2026, 2:45 a.m.

4

CVSS3.1

CVE-2025-9820 - Gnutls: stack-based buffer overflow in gnutls_pkcs11_token_init() function

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the applic…

πŸ“… Published: Jan. 26, 2026, 7:58 p.m. πŸ”„ Last Modified: May 5, 2026, 5:50 p.m.

3.3

CVSS3.0

CVE-2025-9615 - Networkmanager: networkmanager file access

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the…

πŸ“… Published: Jan. 26, 2026, 7:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-11687 - Gi-docgen: reflected dom xss in gi-docgen

A flaw was found in the gi-docgen. This vulnerability allows arbitrary JavaScript execution in the context of the page β€” enabling DOM access, session cookie theft and other client-side attacks β€” via a crafted URL that supplies a malicious value to the q GET parameter (reflected DOM XSS).

πŸ“… Published: Jan. 26, 2026, 7:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-9522 - Blind Server-Side Request Forgery (SSRF) in Omada Controller

Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.

πŸ“… Published: Jan. 26, 2026, 7:35 p.m. πŸ”„ Last Modified: March 11, 2026, 10:30 p.m.

2.1

CVSS4.0

CVE-2025-9521 - Password Confirmation Bypass in Omada Controller

Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification,Β and change the user’s password without proper confirmation, leading to weakened account security.

πŸ“… Published: Jan. 26, 2026, 7:35 p.m. πŸ”„ Last Modified: March 11, 2026, 10:43 p.m.

8.3

CVSS4.0

CVE-2025-9520 - IDOR Leading to Owner Account Hijacking in Omada Controller

An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.

πŸ“… Published: Jan. 26, 2026, 7:34 p.m. πŸ”„ Last Modified: March 11, 2026, 10:43 p.m.
Total resulsts: 349182
Page 1944 of 34,919
Β« previous page Β» next page
Filters