7.2

CVSS4.0

CVE-2026-22849 - Saleor lacks proper HTML sanitization in rich text fields

Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor was allowing users to modify rich text fields with HTML without running any backend HTML cleaners thus allowing malicious actors to perform stored XSS attacks on dashboards and s…

πŸ“… Published: Jan. 21, 2026, 9:31 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

9.3

CVSS4.0

CVE-2026-22822 - External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider,…

πŸ“… Published: Jan. 21, 2026, 9:22 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

5.5

CVSS4.0

CVE-2026-22808 - Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

fleetdm/fleet is open source device management software. Prior to versions 4.78.2, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, if Windows MDM is enabled, an unauthenticated attacker can exploit this XSS vulnerability to steal a Fleet administrator's authentication token (FLEET::auth_token) from localStorag…

πŸ“… Published: Jan. 21, 2026, 9:18 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

8.8

CVSS3.1

CVE-2026-22807 - vLLM affected by RCE via auto_map dynamic module loading during model initialization

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_code`, allowing attacker-controlled Python code in a model rep…

πŸ“… Published: Jan. 21, 2026, 9:13 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

9.7

CVSS3.1

CVE-2026-22793 - 5ire vulnerable to Remote Code Execution (RCE) via ECharts

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the rendere…

πŸ“… Published: Jan. 21, 2026, 9:06 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

9.7

CVSS3.1

CVE-2026-22792 - 5ire vulnerable to Remote Code Execution (RCE)

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML rendering permits untrusted HTML (including on* event attributes) to execute in the renderer context. An attacker can inject an `<img onerror=...>` payload t…

πŸ“… Published: Jan. 21, 2026, 8:54 p.m. πŸ”„ Last Modified: April 18, 2026, 3:45 p.m.

7.1

CVSS4.0

CVE-2026-22598 - ManageIQ vulnerable to DoS Attack when creating TimeProfiles

ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a malformed TimeProfile could be created causing later UI and API requests to timeout leading to a Denial of Service. Version radjabov-2 contains a patch. One may also apply the pa…

πŸ“… Published: Jan. 21, 2026, 8:51 p.m. πŸ”„ Last Modified: April 18, 2026, 4:15 a.m.

5.3

CVSS4.0

CVE-2026-21852 - Claude Code Leaks Data via Malicious Environment Configuration Before Trust Confirmation

Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed malicious repositories to exfiltrate data including Anthropic API keys before users confirmed trust. An attacker-controlled repository could include a settings file that sets ANT…

πŸ“… Published: Jan. 21, 2026, 8:42 p.m. πŸ”„ Last Modified: April 18, 2026, 3:45 p.m.

7.7

CVSS4.0

CVE-2025-69285 - SQLBot uploadExcel Endpoint has Unauthenticated Arbitrary File Upload vulnerability

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerability in the /api/v1/datasource/uploadExcel endpoint, allowing a remote unauthenticated attacker to upload arbitrary Excel/CSV files and inject data d…

πŸ“… Published: Jan. 21, 2026, 8:05 p.m. πŸ”„ Last Modified: Feb. 2, 2026, 1:57 p.m.

6.9

CVSS4.0

CVE-2025-69209 - ArduinoCore-avr has Stack-Based Buffer Overflow in WString Float/Double Constructors

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.7 allows an attacker to trigger a stack-based buffer overflow when converting floating-point values to strings with high precision. By passing very large `de…

πŸ“… Published: Jan. 21, 2026, 8 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2037 of 34,919
Β« previous page Β» next page
Filters