0.0

CVE-2026-24021 -

Not used

πŸ“… Published: Jan. 20, 2026, 11:13 a.m. πŸ”„ Last Modified: Jan. 21, 2026, 3:55 a.m.

0.0

CVE-2026-24020 -

Not used

πŸ“… Published: Jan. 20, 2026, 11:13 a.m. πŸ”„ Last Modified: Jan. 21, 2026, 3:55 a.m.

0.0

CVE-2026-24025 -

Not used

πŸ“… Published: Jan. 20, 2026, 11:13 a.m. πŸ”„ Last Modified: Jan. 21, 2026, 3:55 a.m.

0.0

CVE-2026-24022 -

Not used

πŸ“… Published: Jan. 20, 2026, 11:13 a.m. πŸ”„ Last Modified: Jan. 21, 2026, 3:55 a.m.

9.8

CVSS3.1

CVE-2025-14533 - Advanced Custom Fields: Extended <= 0.9.2.1 - Unauthenticated Privilege Escalation via Insert User …

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to …

πŸ“… Published: Jan. 20, 2026, 9:25 a.m. πŸ”„ Last Modified: April 20, 2026, 9:15 p.m.

5.1

CVSS4.0

CVE-2025-41084 - Stored Cross-Site Scripting (XSS) in Sesame web application

Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts in SVG files by sending a POST request using the 'logo' parameter in '/api/v3/companies/<ID>/logo', which …

πŸ“… Published: Jan. 20, 2026, 9:14 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-41768 - Beckhoff: XSS Vulnerability in TwinCAT 3 HMI Server

An high privileged remote attacker can inject arbitrary content into the custom CSS field on the affected devices due to improper neutralization of input during web page generation ('Cross-site Scripting').

πŸ“… Published: Jan. 20, 2026, 8:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.2

CVSS4.0

CVE-2026-0895 - Insecure Deserialization in extension "Mailqueue" (mailqueue)

The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-SA-2026-004 https://typo3.org/security/advisory/typo3-core-sa-2026-004 . Since the related fix is overwritten by the extension, using the extension with a patched TYPO3 core versi…

πŸ“… Published: Jan. 20, 2026, 7:19 a.m. πŸ”„ Last Modified: April 18, 2026, 5 a.m.

6.1

CVSS3.1

CVE-2025-66523 - Reflected Cross-Site Scripting (XSS) Vulnerability in na1.foxitesign.foxit.com via Unsanitized URL …

URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. This allows attackers to inject arbitrary scripts when an authenticated user visits a crafted link. This issue affects na1.foxitesign.foxit.com: before 2026‑01‑16.

πŸ“… Published: Jan. 20, 2026, 6:51 a.m. πŸ”„ Last Modified: April 9, 2026, 2:48 p.m.

6.9

CVSS4.0

CVE-2026-1223 - BROWAN COMMUNICATIONS |PrismX MX100 AP controller - Insufficiently Protected Credentials

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has an Insufficiently Protected Credentials vulnerability, allowing privileged remote attackers to allowing authenticated remote attackers to obtain SMTP plaintext passwords through the web frontend.

πŸ“… Published: Jan. 20, 2026, 6:35 a.m. πŸ”„ Last Modified: April 18, 2026, 5 a.m.
Total resulsts: 349182
Page 2064 of 34,919
Β« previous page Β» next page
Filters