5.1

CVSS4.0

CVE-2026-1161 - pbrong hrms recruitment.go UpdateRecruitmentById cross site scripting

A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the file /handler/recruitment.go. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

πŸ“… Published: Jan. 19, 2026, 4:02 p.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

8.9

CVSS4.0

CVE-2025-11044 - Vulnerability on Automation Runtime my cause DoS Conditions

An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (…

πŸ“… Published: Jan. 19, 2026, 3:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS4.0

CVE-2025-11043 - Improper Server Certificate Validation in Automation Studio

An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges.

πŸ“… Published: Jan. 19, 2026, 3:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-1160 - PHPGurukul Directory Management System Search index.php sql injection

A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been di…

πŸ“… Published: Jan. 19, 2026, 3:32 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

8.4

CVSS3.1

CVE-2026-22031 - Fastify Middie Middleware Path Bypass

@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., `/%61dmin` instead of `/admin`). W…

πŸ“… Published: Jan. 19, 2026, 3:24 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

7.5

CVSS3.1

CVE-2025-68616 - WeasyPrint Vulnerable to Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect

WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (such as `localhost` services or cloud metadat…

πŸ“… Published: Jan. 19, 2026, 3:20 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:03 p.m.

7.5

CVSS3.1

CVE-2025-61684 - Quicly has assertion failures

Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using Quicly. Commit d9d3df6a8530a102b57d840e39b0311ce5c…

πŸ“… Published: Jan. 19, 2026, 3:18 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 7:41 p.m.

6.9

CVSS4.0

CVE-2026-1159 - itsourcecode Online Frozen Foods Ordering System order_online.php sql injection

A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This issue affects some unknown processing of the file /order_online.php. Executing a manipulation of the argument product_name can lead to sql injection. The attack can be launched remotely. The exploit has bee…

πŸ“… Published: Jan. 19, 2026, 3:02 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

8.7

CVSS4.0

CVE-2026-1158 - Totolink LR350 POST Request cstecgi.cgi setWizardCfg buffer overflow

A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. Performing a manipulation of the argument ssid results in buffer overflow. The attack can be init…

πŸ“… Published: Jan. 19, 2026, 2:32 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.

7.6

CVSS3.1

CVE-2026-1007 -

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

πŸ“… Published: Jan. 19, 2026, 2:32 p.m. πŸ”„ Last Modified: April 18, 2026, 5:15 a.m.
Total resulsts: 349182
Page 2077 of 34,919
Β« previous page Β» next page
Filters