6.5

CVSS3.1

CVE-2026-21923 - Unauthenticated HTTP Data Modification and Disclosure in Oracle Life Sciences Central Designer

Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Li…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 4:45 a.m.

4.2

CVSS3.1

CVE-2026-21922 - Compromise of Oracle Planning and Budgeting Cloud Service via privileged EPM Agent vulnerability

Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budge…

📅 Published: Jan. 20, 2026, 9:56 p.m. 🔄 Last Modified: April 18, 2026, 3:45 p.m.

6

CVSS4.0

CVE-2026-0672 - Header injection in http.cookies.Morsel

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

📅 Published: Jan. 20, 2026, 9:52 p.m. 🔄 Last Modified: April 16, 2026, 6:15 p.m.

5.9

CVSS4.0

CVE-2025-15367 - POP3 command injection in user-controlled commands

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

📅 Published: Jan. 20, 2026, 9:47 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2025-15366 - IMAP command injection in user-controlled commands

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

📅 Published: Jan. 20, 2026, 9:40 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-58744 - Hard-Coded Default Credentials Enable Document Archive Decryption in Milner ImageDirector Capture

Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key. This issue affects ImageDirector Capture: from…

📅 Published: Jan. 20, 2026, 9:38 p.m. 🔄 Last Modified: Feb. 10, 2026, 4:48 p.m.

7.2

CVSS4.0

CVE-2025-58743 - Insecure Encryption Algorithms Enable Brute-Force Database Credential Access in Milner ImageDirecto…

Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brute Forcing to obtain database credentials.This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808.

📅 Published: Jan. 20, 2026, 9:37 p.m. 🔄 Last Modified: Feb. 10, 2026, 4:43 p.m.

8.5

CVSS4.0

CVE-2025-58742 - Insufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirec…

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authenticatio…

📅 Published: Jan. 20, 2026, 9:36 p.m. 🔄 Last Modified: Feb. 10, 2026, 4:51 p.m.

8.5

CVSS4.0

CVE-2025-58741 - Insecure Masked Credential Fields Enable Database Credential Access in Milner ImageDirector Capture

Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This issue affects ImageDirector Capture: from 7.0.9 through 7.6.3.25808.

📅 Published: Jan. 20, 2026, 9:36 p.m. 🔄 Last Modified: Feb. 10, 2026, 4:52 p.m.

8.5

CVSS4.0

CVE-2025-58740 - Hardcoded Encryption Key Enables Database Credential Access in Milner ImageDirector Capture

The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from …

📅 Published: Jan. 20, 2026, 9:36 p.m. 🔄 Last Modified: Feb. 10, 2026, 4:53 p.m.
Total resulsts: 349182
Page 2052 of 34,919
« previous page » next page
Filters