4.9

CVSS3.1

CVE-2026-21964 - mysql: Thread Pooling unspecified vulnerability (CPU Jan 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromโ€ฆ

๐Ÿ“… Published: Jan. 20, 2026, midnight ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2025-57156 -

NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).

๐Ÿ“… Published: Jan. 20, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 13, 2026, 9:04 p.m.

6.5

CVSS3.1

CVE-2024-31884 - pybind: Improper use of Pybind

No description is available for this CVE.

๐Ÿ“… Published: Jan. 20, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 20, 2026, midnight

6.9

CVSS4.0

CVE-2026-1194 - MineAdmin Swagger information disclosure

A security flaw has been discovered in MineAdmin 1.x/2.x. This affects an unknown function of the component Swagger. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was cโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 11:32 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:15 p.m.

5.4

CVSS3.1

CVE-2025-15466 - Image Photo Gallery Final Tiles Grid <= 3.6.9 - Missing Authorization to Authenticated (Contributorโ€ฆ

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple AJAX actions in all versions up to, and including, 3.6.9. This makes it possible for authenticated attackers, with Contributor-levโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 11:21 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:15 p.m.

8.3

CVSS4.0

CVE-2026-22219 - Chainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element

Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with the SQLAlchemy data layer backend. An authenticated client can provide a user-controlled url value in an Element, which is fetched by the SQLAlchemy eโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 11:15 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.

7.1

CVSS4.0

CVE-2026-22218 - Chainlit < 2.9.4 Arbitrary File Read via /project/element

Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a custom Element with a user-controlled path value, causing the server to copy the referenced file into the attackerโ€™s session. The resulting element iโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:15 p.m.

5.3

CVSS4.0

CVE-2026-1193 - MineAdmin View view improper authorization

A vulnerability was identified in MineAdmin 1.x/2.x. The impacted element is an unknown function of the file /system/cache/view of the component View Interface. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available andโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 11:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.

6.9

CVSS4.0

CVE-2026-1192 - Tosei Online Store Management System ใƒใƒƒใƒˆๅบ—่ˆ—็ฎก็†ใ‚ทใ‚นใƒ†ใƒ  imode_alldata.php command injection

A vulnerability was determined in Tosei Online Store Management System ใƒใƒƒใƒˆๅบ—่ˆ—็ฎก็†ใ‚ทใ‚นใƒ†ใƒ  1.01. The affected element is an unknown function of the file /cgi-bin/imode_alldata.php. Executing a manipulation of the argument DevId can lead to command injection. The attack can be executed remotely. The exploitโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 11:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.

6.9

CVSS4.0

CVE-2026-1179 - Yonyou KSOA HTTP GET Parameter user_popedom.jsp sql injection

A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument folderid results in sql injection. The attack can be launched remotely. The exploit is now public and may be โ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 10:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 a.m.
Total resulsts: 349182
Page 2070 of 34,919
ยซ previous page ยป next page
Filters