6.8

CVSS4.0

CVE-2025-59959 - Junos OS and Junos OS Evolved: Executing a specific show command leads to an rpd crash

An Untrusted Pointer Dereference vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated attacker with low privileges to cause a Denial-of-Service (DoS). When the command 'show route < ( receive-protocol | advertising-proto…

📅 Published: Jan. 15, 2026, 8:13 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:38 p.m.

5.1

CVSS4.0

CVE-2025-52987 - Paragon Automation: A clickjacking vulnerability in the web server configuration has been addressed

A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting wit…

📅 Published: Jan. 15, 2026, 8:10 p.m. 🔄 Last Modified: Jan. 26, 2026, 6:01 p.m.

5.3

CVSS4.0

CVE-2025-15265 - Svelte 5.46.0 - Hydratable Key Script-Breakout XSS (SSR)

An SSR XSS exists in async hydration when attacker‑controlled keys are passed to hydratable. The key is embedded inside a <script> block without HTML‑safe escaping, allowing </script> to terminate the script and inject arbitrary JavaScript. This enables remote script execution in users' browsers, w…

📅 Published: Jan. 15, 2026, 7:59 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:04 p.m.

9.3

CVSS4.0

CVE-2026-23746 - Entrust Instant Financial Issuance (IFI) SmartCardController Service .NET Remoting RCE

Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 contain an insecure .NET Remoting exposure in the SmartCardController service (DCG.SmartCardControllerService.exe). The service registers a TCP remoti…

📅 Published: Jan. 15, 2026, 7:44 p.m. 🔄 Last Modified: April 16, 2026, 8 a.m.

7.4

CVSS4.0

CVE-2026-23622 - CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover

Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters fro…

📅 Published: Jan. 15, 2026, 7:28 p.m. 🔄 Last Modified: April 18, 2026, 4:15 p.m.

8.9

CVSS3.1

CVE-2026-23527 - h3 v1 has Request Smuggling (TE.TE) issue

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this heade…

📅 Published: Jan. 15, 2026, 7:24 p.m. 🔄 Last Modified: April 15, 2026, 6:15 p.m.

9.1

CVSS3.1

CVE-2026-23520 - Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run…

📅 Published: Jan. 15, 2026, 7:20 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

4.1

CVSS3.1

CVE-2026-23766 - istio: From CVEorg collector

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

📅 Published: Jan. 15, 2026, 7:18 p.m. 🔄 Last Modified: Feb. 14, 2026, 5:44 p.m.

8.9

CVSS4.0

CVE-2026-23519 - RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (…

📅 Published: Jan. 15, 2026, 7:13 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

5.3

CVSS3.1

CVE-2026-23511 - ZITADEL has a user enumeration vulnerability in Login UIs

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and …

📅 Published: Jan. 15, 2026, 7:09 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.
Total resulsts: 349182
Page 2112 of 34,919
« previous page » next page
Filters