3.7

CVSS3.1

CVE-2026-22611 - AWS SDK for .NET V4 adopted defense in depth enhancement for region parameter value

AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notif…

📅 Published: Jan. 10, 2026, 5:37 a.m. 🔄 Last Modified: Jan. 10, 2026, 5:37 a.m.

7.5

CVSS3.1

CVE-2026-22700 - RustCrypto Has Insufficient Length Validation in decrypt() in SM2-PKE

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability e…

📅 Published: Jan. 10, 2026, 5:17 a.m. 🔄 Last Modified: Jan. 10, 2026, 5:17 a.m.

7.5

CVSS3.1

CVE-2026-22699 - RustCrypto SM2-PKE has Unchecked AffinePoint Decoding (unwrap) in decrypt()

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a denial-of-service vulnerability e…

📅 Published: Jan. 10, 2026, 5:17 a.m. 🔄 Last Modified: Jan. 10, 2026, 5:17 a.m.

8.7

CVSS4.0

CVE-2026-22698 - RustCrypto SM2-PKE has 32-bit Biased Nonce Vulnerability

RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for representing various elliptic curve forms, scalars, points, and public/secret keys composed thereof. In versions 0.14.0-pre.0 and 0.14.0-rc.0, a critical vulnerability exists in…

📅 Published: Jan. 10, 2026, 5:17 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:48 p.m.

2.7

CVSS4.0

CVE-2026-22691 - pypdf has possible long runtimes for malformed startxref

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for malformed startxref. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for invalid startxref entries. When rebuilding the cross-reference…

📅 Published: Jan. 10, 2026, 4:46 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:48 p.m.

2.7

CVSS4.0

CVE-2026-22690 - pypdf has possible long runtimes for missing /Root object with large /Size values

pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for missing /Root object with large /Size values. An attacker who uses this vulnerability can craft a PDF which leads to possibly long runtimes for actually invalid files. This can be a…

📅 Published: Jan. 10, 2026, 4:41 a.m. 🔄 Last Modified: Jan. 12, 2026, 5:07 p.m.

10

CVSS3.1

CVE-2026-22688 - WeKnora has Command Injection in MCP stdio test

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subproce…

📅 Published: Jan. 10, 2026, 3:41 a.m. 🔄 Last Modified: Jan. 12, 2026, 5:20 p.m.

8.1

CVSS3.1

CVE-2026-22687 - WeKnora vulnerable to SQL Injection

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass tech…

📅 Published: Jan. 10, 2026, 3:41 a.m. 🔄 Last Modified: Jan. 12, 2026, 5:21 p.m.

8.5

CVSS4.0

CVE-2026-22610 - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulne…

📅 Published: Jan. 10, 2026, 3:35 a.m. 🔄 Last Modified: Jan. 12, 2026, 5:30 p.m.

7.5

CVSS3.1

CVE-2025-13457 - WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Informa…

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Sq…

📅 Published: Jan. 10, 2026, 3:21 a.m. 🔄 Last Modified: Jan. 12, 2026, 4:49 p.m.
Total resulsts: 327160
Page 20 of 32,716
« previous page » next page
Filters