8.7

CVSS4.0

CVE-2026-22787 - html2pdf.js has a cross-site scripting vulnerability

html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing…

πŸ“… Published: Jan. 14, 2026, 4:52 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.3

CVSS4.0

CVE-2026-22779 - BlackSheep ClientSession is vulnerable to CRLF injection

BlackSheep is an asynchronous web framework to build event based web applications with Python. Prior to 2.4.6, the HTTP Client implementation in BlackSheep is vulnerable to CRLF injection. Missing headers validation makes it possible for an attacker to modify the HTTP requests (e.g. insert a new he…

πŸ“… Published: Jan. 14, 2026, 4:49 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

7.2

CVSS4.0

CVE-2026-22708 - Cursor has a Terminal Tool Allowlist Bypass via Environment Variables

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without requiring user approval. This allows an attacker via indire…

πŸ“… Published: Jan. 14, 2026, 4:43 p.m. πŸ”„ Last Modified: April 18, 2026, 6:30 a.m.

6.1

CVSS3.1

CVE-2026-22694 - AliasVault is Missing Origin Validation in Android Passkey Credential Provider

AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for …

πŸ“… Published: Jan. 14, 2026, 4:32 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

2.3

CVSS4.0

CVE-2026-21889 - Weblate leaks information via screenshots

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

πŸ“… Published: Jan. 14, 2026, 4:28 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

7.2

CVSS3.1

CVE-2025-37181 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading …

πŸ“… Published: Jan. 14, 2026, 4:26 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:17 p.m.

5.5

CVSS3.1

CVE-2025-37185 - Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator …

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary …

πŸ“… Published: Jan. 14, 2026, 4:20 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:14 p.m.

9.8

CVSS3.1

CVE-2025-37184 - Unauthenticated Bypass Allows Multi-Factor Authentication Circumvention

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compro…

πŸ“… Published: Jan. 14, 2026, 4:19 p.m. πŸ”„ Last Modified: March 3, 2026, 6:16 p.m.

7.2

CVSS3.1

CVE-2025-37183 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading …

πŸ“… Published: Jan. 14, 2026, 4:18 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:17 p.m.

7.2

CVSS3.1

CVE-2025-37182 - Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading …

πŸ“… Published: Jan. 14, 2026, 4:17 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:17 p.m.
Total resulsts: 349182
Page 2129 of 34,919
Β« previous page Β» next page
Filters