5.4

CVSS3.1

CVE-2026-23496 - Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Auth…

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing revealed that an authen…

📅 Published: Jan. 15, 2026, 4:58 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

4.3

CVSS3.1

CVE-2026-23494 - Pimcore is Missing Function Level Authorization on "Static Routes" Listing

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for reading or listing static routes. In Pimcore, static routes are custom URL patterns defined via …

📅 Published: Jan. 15, 2026, 4:52 p.m. 🔄 Last Modified: April 18, 2026, 4:15 p.m.

4.3

CVSS3.1

CVE-2026-23495 - Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" L…

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type…

📅 Published: Jan. 15, 2026, 4:47 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

9.3

CVSS4.0

CVE-2025-62193 - NOAA PMEL Live Access Server (LAS) PyFerret command injection

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of 'gov.noaa.pmel.tmap.l…

📅 Published: Jan. 15, 2026, 4:44 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2026-23493 - Pimcore ENV Variables and Cookie Informations are exposed in http_error_log

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed or recovered through…

📅 Published: Jan. 15, 2026, 4:38 p.m. 🔄 Last Modified: April 18, 2026, 7:15 p.m.

4.8

CVSS3.1

CVE-2026-20075 - Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripti…

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This…

📅 Published: Jan. 15, 2026, 4:32 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

4.8

CVSS3.1

CVE-2026-20047 - Cisco Identity Services Engine Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due …

📅 Published: Jan. 15, 2026, 4:32 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

4.8

CVSS3.1

CVE-2026-20076 - Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied…

📅 Published: Jan. 15, 2026, 4:32 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

8.7

CVSS3.1

CVE-2026-22867 - LaSuite Doc affected by Stored XSS via Interlinking Block

LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Interlinking feature. When a user creates a link to another document within the editor, the URL of that link is not validated. An attacke…

📅 Published: Jan. 15, 2026, 4:31 p.m. 🔄 Last Modified: April 18, 2026, 6:15 a.m.

7.5

CVSS3.1

CVE-2026-22265 - Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticated RCE

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py l…

📅 Published: Jan. 15, 2026, 4:27 p.m. 🔄 Last Modified: April 18, 2026, 4:15 p.m.
Total resulsts: 349182
Page 2114 of 34,919
« previous page » next page
Filters