5.3

CVSS4.0

CVE-2026-1327 - Totolink NR1800X POST Request cstecgi.cgi setTracerouteCfg command injection

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Such manipulation of the argument command leads to command injection. The attack can be launโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 2:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

7.5

CVSS3.1

CVE-2025-13928 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrect authorization validation in API endpoints.

๐Ÿ“… Published: Jan. 22, 2026, 1:34 p.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 9:08 p.m.

7.5

CVSS3.1

CVE-2025-13927 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

๐Ÿ“… Published: Jan. 22, 2026, 1:34 p.m. ๐Ÿ”„ Last Modified: Jan. 26, 2026, 9:07 p.m.

7.4

CVSS3.1

CVE-2026-0723 - Unchecked Return Value in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an individual with existing knowledge of a victim's credential ID to bypass two-factor authentication by submitting forged device responsโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:34 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

5.3

CVSS3.1

CVE-2026-1102 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.

๐Ÿ“… Published: Jan. 22, 2026, 1:33 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

5.3

CVSS4.0

CVE-2026-1326 - Totolink NR1800X POST Request cstecgi.cgi setWanCfg command injection

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. This manipulation of the argument Hostname causes command injection. The attack can be initiated remoteโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:30 p.m.

1.3

CVSS4.0

CVE-2025-12738 - Enumeration of restricted property value

Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some legitimate access to the database. The vulnerability allows attacker without read access to a property to infer information about its value by trying to โ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:29 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-1325 - Sangfor Operation and Maintenance Security Management System edit_pwd_mall password recovery

A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attaโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 a.m.

8.7

CVSS4.0

CVE-2026-1324 - Sangfor Operation and Maintenance Management System SSH Protocol session SessionController os commaโ€ฆ

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os cโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 1:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:30 p.m.

7

CVSS4.0

CVE-2025-14295 - Automated Logic WebCTRL and Carrier i-Vu Session Fixation

Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows.ย Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format whiโ€ฆ

๐Ÿ“… Published: Jan. 22, 2026, 12:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2027 of 34,919
ยซ previous page ยป next page
Filters