2.7

CVSS4.0

CVE-2026-21895 - rsa crate has potential panic on a prime being equal to 1

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.

πŸ“… Published: Jan. 8, 2026, 2:06 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

5.3

CVSS3.1

CVE-2026-21892 - Parsl Monitoring Visualization Vulnerable to SQL Injection

Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python % operator) with user-supplied input (workflow_id) directly from URL rou…

πŸ“… Published: Jan. 8, 2026, 2:02 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

9.4

CVSS3.1

CVE-2026-21891 - ZimaOS has Authentication Bypass via System-Level Username

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a know…

πŸ“… Published: Jan. 8, 2026, 2 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

6.5

CVSS3.1

CVE-2026-21885 - Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources

Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen med…

πŸ“… Published: Jan. 8, 2026, 1:57 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

9.3

CVSS3.1

CVE-2026-21876 - OWASP CRS has multipart bypass using multiple content-type parts

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a co…

πŸ“… Published: Jan. 8, 2026, 1:55 p.m. πŸ”„ Last Modified: April 16, 2026, 9 a.m.

5.9

CVSS4.0

CVE-2025-8307 - Recoverable passwords in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedd…

πŸ“… Published: Jan. 8, 2026, 1:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-8306 - Improper Access Control in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due to lack of granularity in access control.Β  Chained exploita…

πŸ“… Published: Jan. 8, 2026, 1:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-69260 -

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 7:11 p.m.

7.5

CVSS3.1

CVE-2025-69259 -

A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability..

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 7:14 p.m.

9.8

CVSS3.1

CVE-2025-69258 -

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.
Total resulsts: 346571
Page 1965 of 34,658
Β« previous page Β» next page
Filters