8.3

CVSS3.1

CVE-2026-0603 - Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order โ€ฆ

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information โ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 10:10 a.m. ๐Ÿ”„ Last Modified: May 6, 2026, 2:34 p.m.

5.3

CVSS4.0

CVE-2026-1149 - Totolink LR350 POST Request cstecgi.cgi setDiagnosisCfg command injection

A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be initiated remotely. The eโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 10:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:30 a.m.

5.3

CVSS4.0

CVE-2026-1148 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System cross-site request forgeโ€ฆ

A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown code. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely.

๐Ÿ“… Published: Jan. 19, 2026, 9:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:30 a.m.

5.1

CVSS4.0

CVE-2026-1147 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System api_patient_schedule.phpโ€ฆ

A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attacโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 9:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:30 a.m.

6.5

CVSS3.1

CVE-2025-59355 - Apache Linkis: Password Exposure

A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive information such as Hive Metastore keys, plaintโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 8:37 a.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 9:11 p.m.

7.5

CVSS3.1

CVE-2025-29847 - Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the system's checks. This bypass can triggeโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 8:36 a.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 9:12 p.m.

5.1

CVSS4.0

CVE-2026-1146 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System api_register_patient.phpโ€ฆ

A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The aโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 8:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:30 a.m.

6.3

CVSS3.1

CVE-2026-1200 - Remote code execution via segmentation fault in increasebufferto function

A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `increaseBufferTo` function. This vulnerability can lead to memory corruption problems and potentially other consequences.

๐Ÿ“… Published: Jan. 19, 2026, 8:08 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 6:45 p.m.

3.1

CVSS3.1

CVE-2026-1190 - Org.keycloak/keycloak-services: keycloak saml brokering: response delay due to unchecked notonoraftโ€ฆ

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML โ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 8:08 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8 p.m.

5.3

CVSS4.0

CVE-2026-1145 - quickjs-ng quickjs quickjs.c js_typed_array_constructor_ta heap-based overflow

A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and maโ€ฆ

๐Ÿ“… Published: Jan. 19, 2026, 8:02 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 4 p.m.
Total resulsts: 349182
Page 2080 of 34,919
ยซ previous page ยป next page
Filters