6.1

CVSS3.1

CVE-2025-66686 -

A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the β€œHelp button url” setting within the admin panel. The injected payload is stored and executed when any authentica…

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 10:07 p.m.

7.5

CVSS3.1

CVE-2025-66786 -

OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface to launch a denial-of-service attack.

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:06 a.m.

6.8

CVSS3.1

CVE-2025-66837 -

A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 10:05 p.m.

7.5

CVSS3.1

CVE-2025-67366 -

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism:…

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:02 a.m.

6.5

CVSS3.1

CVE-2025-61489 -

A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:13 a.m.

8.8

CVSS3.1

CVE-2026-0628 - Privilege Escalation via Malicious Extension in Chrome's WebView Tag

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

πŸ“… Published: Jan. 6, 2026, 11:57 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

6.9

CVSS4.0

CVE-2026-0643 - projectworlds House Rental and Property Listing Signup register.php unrestricted upload

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The expl…

πŸ“… Published: Jan. 6, 2026, 11:32 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

7.8

CVSS3.1

CVE-2025-47396 - Double Free in Graphics

Memory corruption occurs when a secure application is launched on a device with insufficient memory.

πŸ“… Published: Jan. 6, 2026, 10:48 p.m. πŸ”„ Last Modified: Jan. 27, 2026, 7:15 p.m.

6.5

CVSS3.1

CVE-2025-47395 - Buffer Over-read in WLAN Firmware

Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

πŸ“… Published: Jan. 6, 2026, 10:48 p.m. πŸ”„ Last Modified: Jan. 27, 2026, 7:16 p.m.

7.8

CVSS3.1

CVE-2025-47394 - Buffer Copy Without Checking Size of Input in DSP Service

Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.

πŸ“… Published: Jan. 6, 2026, 10:48 p.m. πŸ”„ Last Modified: Jan. 27, 2026, 7:19 p.m.
Total resulsts: 346187
Page 1963 of 34,619
Β« previous page Β» next page
Filters