7.5

CVSS3.1

CVE-2026-23965 - sm-crypto Affected by Signature Forgery in SM2-DSA

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature forgery vulnerability exists in the SM2 signature verification logic of sm-crypto prior to version 0.4.0. Under default configurations, an attacker can forge valid signatures for arb…

📅 Published: Jan. 22, 2026, 2:05 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

7.5

CVSS3.1

CVE-2026-23967 - sm-crypto Affected by Signature Malleability in SM2-DSA

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library prior to version 0.3.14. An attacker can derive a new valid signature for a previou…

📅 Published: Jan. 22, 2026, 1:59 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

6.9

CVSS4.0

CVE-2026-23959 - CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier

CoreShop is a Pimcore enhanced eCommerce solution. An error-based SQL Injection vulnerability was identified in versions prior to 4.1.9 in the `CustomerTransformerController` within the CoreShop admin panel. The affected endpoint improperly interpolates user-supplied input into a SQL query, leading…

📅 Published: Jan. 22, 2026, 1:57 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

6.5

CVSS3.1

CVE-2026-23964 - Mastodon has insufficient access control to push notification settings

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessing or obtaining the …

📅 Published: Jan. 22, 2026, 1:55 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

4.3

CVSS3.1

CVE-2026-23963 - Mastodon missing length limits on list names, filter names, and filter keywords

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as the name or keyword…

📅 Published: Jan. 22, 2026, 1:53 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

7.5

CVSS3.1

CVE-2026-23962 - Mastodon vulnerable to Denial of Service from a single post (client/server)

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a very large amount of options, greatly increasing re…

📅 Published: Jan. 22, 2026, 1:51 a.m. 🔄 Last Modified: April 18, 2026, 3:30 p.m.

5.3

CVSS3.1

CVE-2026-23961 - Mastodon may allow a remote suspension bypass

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent interactions. However, some logic errors allow already-known posts from such suspended users to appear in timelines if boosted. Furthermore, under cer…

📅 Published: Jan. 22, 2026, 1:47 a.m. 🔄 Last Modified: April 18, 2026, 4 a.m.

8.8

CVSS4.0

CVE-2026-23958 - DataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Fu…

Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s password by exploiting unmonitored API endpoints tha…

📅 Published: Jan. 22, 2026, 1:42 a.m. 🔄 Last Modified: April 18, 2026, 4:15 a.m.

8.6

CVSS4.0

CVE-2026-23699 - OS Command Injection in Ruijie AP180 Series Allowing Arbitrary Command Execution

AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exploited, arbitrary commands may be executed on the devices.

📅 Published: Jan. 22, 2026, 1:41 a.m. 🔄 Last Modified: April 18, 2026, 4:15 a.m.

7.6

CVSS3.1

CVE-2025-27380 - HTML Injection Leading to Script Execution in Altium Enterprise Server

HTML injection in Project Release in Altium Enterprise Server (AES) 7.0.3 on all platforms allows an authenticated attacker to execute arbitrary JavaScript in the victim’s browser via crafted HTML content.

📅 Published: Jan. 22, 2026, 1:28 a.m. 🔄 Last Modified: Feb. 26, 2026, 9:23 p.m.
Total resulsts: 349182
Page 2032 of 34,919
« previous page » next page
Filters