7.5

CVSS3.1

CVE-2026-23957 - seroval is vulnerable to Denial of Service via array serialization

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time…

πŸ“… Published: Jan. 22, 2026, 1:26 a.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

7.5

CVSS3.1

CVE-2026-23956 - seroval affected by Denial of Service via RegExp serialization

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp ser…

πŸ“… Published: Jan. 22, 2026, 1:23 a.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

6.8

CVSS3.1

CVE-2025-27379 - Stored Cross-Site Scripting in AES BOM Viewer

A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content.

πŸ“… Published: Jan. 22, 2026, 1:17 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 9:24 p.m.

8.6

CVSS3.1

CVE-2025-27378 - SQL Injection in AES Due to Inactive SQL Parsing Configuration

AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to inject and execute arbitrary SQL queries.

πŸ“… Published: Jan. 22, 2026, 1:06 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 9:25 p.m.

6.5

CVSS3.1

CVE-2026-23952 - ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack …

πŸ“… Published: Jan. 22, 2026, 12:32 a.m. πŸ”„ Last Modified: April 18, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2026-23951 - SumatraPDF's Integer Underflow in PalmDbReader Leads to Crash

SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 records, causing an integer underflow in the size calculation. This bug exists in PalmDbReader::GetRecord when opening a crafted Mobi file, resulting in…

πŸ“… Published: Jan. 22, 2026, 12:17 a.m. πŸ”„ Last Modified: April 18, 2026, 7 p.m.

5.3

CVSS3.1

CVE-2025-27377 - Missing Validation of Self-Signed Certificates in Altium Designer Allows Man-in-the-Middle Attacks

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensiti…

πŸ“… Published: Jan. 22, 2026, 12:16 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 9:49 p.m.

6.8

CVSS3.1

CVE-2026-23946 - Tendenci has Authenticated Remote Code Execution via Pickle Deserialization

Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a critical deserialization vulnerability in the Helpdesk module (which is not enabled by default). This vulnerability allows Remote Code Execution (RCE)…

πŸ“… Published: Jan. 22, 2026, 12:09 a.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

6.8

CVSS3.1

CVE-2026-23893 - openCryptoki has improper link resolution before file access (link following)

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token di…

πŸ“… Published: Jan. 22, 2026, 12:01 a.m. πŸ”„ Last Modified: April 18, 2026, 7 p.m.

10

CVSS3.1

CVE-2025-69828 -

File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via the Logo upload in /Customer/AddEdit

πŸ“… Published: Jan. 22, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2033 of 34,919
Β« previous page Β» next page
Filters