7.5

CVSS3.1

CVE-2026-0943 - HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dere…

HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.Β  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

πŸ“… Published: Jan. 19, 2026, 2:46 a.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-1134 - itsourcecode Society Management System expenses.php cross site scripting

A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the file /admin/expenses.php. The manipulation of the argument detail leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be…

πŸ“… Published: Jan. 19, 2026, 2:32 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 a.m.

6.9

CVSS4.0

CVE-2026-1133 - Yonyou KSOA HTTP GET Parameter folder.jsp sql injection

A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. The attack can be launched remotely. The exploit has b…

πŸ“… Published: Jan. 19, 2026, 2:02 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 a.m.

6.9

CVSS4.0

CVE-2026-1132 - Yonyou KSOA HTTP GET Parameter edit_folder.jsp sql injection

A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument folderid results in sql injection. The attack can be initiated remotely. The exploit has …

πŸ“… Published: Jan. 19, 2026, 1:32 a.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-1131 - Yonyou KSOA HTTP GET Parameter save_catalog.jsp sql injection

A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The exploit has been di…

πŸ“… Published: Jan. 19, 2026, 1:02 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 a.m.

6.9

CVSS4.0

CVE-2026-1130 - Yonyou KSOA HTTP GET Parameter worksadd_plan.jsp sql injection

A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been …

πŸ“… Published: Jan. 19, 2026, 12:32 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 a.m.

6.9

CVSS4.0

CVE-2026-1129 - Yonyou KSOA HTTP GET Parameter worksadd.jsp sql injection

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public …

πŸ“… Published: Jan. 19, 2026, 12:02 a.m. πŸ”„ Last Modified: April 18, 2026, 4 p.m.

5.8

CVSS3.1

CVE-2026-1180 - Org.keycloak.protocol.oidc: blind server-side request forgery (ssrf) in keycloak oidc dynamic clien…

A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the …

πŸ“… Published: Jan. 19, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:45 p.m.

9.9

CVSS3.1

CVE-2026-22797 - keystonemiddleware: From CVEorg collector

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged …

πŸ“… Published: Jan. 19, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2025-15539 - Open5GS sgwc s11-handler.c sgwc_s11_handle_downlink_data_notification_ack denial of service

A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notification_ack of the file src/sgwc/s11-handler.c of the component sgwc. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly di…

πŸ“… Published: Jan. 18, 2026, 11:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.
Total resulsts: 349182
Page 2082 of 34,919
Β« previous page Β» next page
Filters