1.7

CVSS4.0

CVE-2026-23833 - ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2025.12.6, an integer overflow in the API component's protobuf decoder allows denial-of-service attacks when API encryption is not used. The bounds check `ptr + field_length > end`…

📅 Published: Jan. 19, 2026, 5:58 p.m. 🔄 Last Modified: April 18, 2026, 5:15 a.m.

2.8

CVSS3.1

CVE-2025-52659 - HCL AION is affected by a Cacheable HTTP Response vulnerability

HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.

📅 Published: Jan. 19, 2026, 5:54 p.m. 🔄 Last Modified: April 25, 2026, 6:04 p.m.

4.3

CVSS3.1

CVE-2026-23721 - OpenProject users with "View Members" permission in any project can view all Group memberships

OpenProject is an open-source, web-based project management software. When using groups in OpenProject to manage users, the group members should only be visible to users that have the View Members permission in any project that the group is also a member of. Prior to versions 17.0.1 and 16.6.5, due…

📅 Published: Jan. 19, 2026, 5:52 p.m. 🔄 Last Modified: April 18, 2026, 5:15 a.m.

2.7

CVSS3.1

CVE-2025-52660 - HCL AION is affected by an Host Header Injection vulnerability

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

📅 Published: Jan. 19, 2026, 5:49 p.m. 🔄 Last Modified: April 25, 2026, 6:05 p.m.

6.5

CVSS3.1

CVE-2026-23646 - OpenProject users can delete other user's session, causing them to be logged out

OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a session, it was not properly checked if the session belongs to the u…

📅 Published: Jan. 19, 2026, 5:48 p.m. 🔄 Last Modified: April 18, 2026, 4 p.m.

8.7

CVSS3.1

CVE-2026-23625 - OpenProject has stored XSS regression using attachments and script-src self

OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a stored cross-site scripting vulnerability in the Roadmap view. OpenProject’s roadmap view renders the “Related work packages” list for each version. When a version contains work pa…

📅 Published: Jan. 19, 2026, 5:41 p.m. 🔄 Last Modified: April 18, 2026, 4 p.m.

3.1

CVSS3.1

CVE-2025-55251 - HCL AION is affected by an Unrestricted File Upload vulnerability

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

📅 Published: Jan. 19, 2026, 5:39 p.m. 🔄 Last Modified: April 25, 2026, 6:05 p.m.

5.3

CVSS4.0

CVE-2026-1169 - birkir prime cross-site request forgery

A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of th…

📅 Published: Jan. 19, 2026, 5:32 p.m. 🔄 Last Modified: April 18, 2026, 5:15 a.m.

7.7

CVSS4.0

CVE-2026-23884 - Heap-use-after-free in gdi_set_bounds

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and …

📅 Published: Jan. 19, 2026, 5:20 p.m. 🔄 Last Modified: April 18, 2026, 5:15 a.m.

7.7

CVSS4.0

CVE-2026-23883 - Heap-use-after-free in update_pointer_new

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `pointer_free` calls `xf_Pointer_Free` and frees it again, triggering ASan UAF. A malicious server can trigger a client‑side use after free, causing a cra…

📅 Published: Jan. 19, 2026, 5:15 p.m. 🔄 Last Modified: April 18, 2026, 5:15 a.m.
Total resulsts: 349182
Page 2075 of 34,919
« previous page » next page
Filters