6

CVSS4.0

CVE-2025-15282 - Header injection via newlines in data URL mediatype

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

πŸ“… Published: Jan. 20, 2026, 9:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS4.0

CVE-2026-0865 - wsgiref.headers.Headers allows header newline injection

User-controlled header names and values containing newlines can allow injecting HTTP headers.

πŸ“… Published: Jan. 20, 2026, 9:26 p.m. πŸ”„ Last Modified: April 16, 2026, 6:15 p.m.

7.4

CVSS3.1

CVE-2026-21932 - openjdk: Enhance Handling of URIs (Oracle CPU 2026-01)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.1…

πŸ“… Published: Jan. 20, 2026, 9:21 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 a.m.

6.1

CVSS3.1

CVE-2026-21933 - openjdk: Improve HttpServer Request handling (Oracle CPU 2026-01)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17…

πŸ“… Published: Jan. 20, 2026, 9:21 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 a.m.

4.8

CVSS3.1

CVE-2026-21925 - openjdk: Improve JMX connections (Oracle CPU 2026-01)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 2…

πŸ“… Published: Jan. 20, 2026, 9:21 p.m. πŸ”„ Last Modified: April 18, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2026-21945 - openjdk: Enhance Certificate Checking (Oracle CPU 2026-01)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 a…

πŸ“… Published: Jan. 20, 2026, 9:21 p.m. πŸ”„ Last Modified: April 18, 2026, 8 p.m.

5.7

CVSS4.0

CVE-2025-11468 - Folding email comments of unfoldable characters doesn't preserve parenthesis

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

πŸ“… Published: Jan. 20, 2026, 9:09 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.0

CVE-2026-21642 - Reflected XSS in Revive Adserver Administrator Scripts

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML…

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 8 p.m.

6.1

CVSS3.0

CVE-2026-21664 - Reflected Cross‑Site Scripting in Revive Adserver afr.php Delivery Script

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent …

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 a.m.

6.1

CVSS3.0

CVE-2026-21663 - Reflected XSS in Revive Adserver Banner ACL

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is sent to the browser a…

πŸ“… Published: Jan. 20, 2026, 8:48 p.m. πŸ”„ Last Modified: April 18, 2026, 7:15 p.m.
Total resulsts: 349182
Page 2053 of 34,919
Β« previous page Β» next page
Filters