6.5

CVSS3.1

CVE-2025-66715 -

A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:44 p.m.

5.4

CVSS3.1

CVE-2025-67280 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:33 p.m.

6.5

CVSS3.1

CVE-2025-67810 -

In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 7:45 p.m.

2.3

CVSS4.0

CVE-2026-22714 - i18n XSS, DoS and config SQLI in Monaco

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Monaco Skin allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Monaco Skin: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 8, 2026, 11:56 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

2.3

CVSS4.0

CVE-2026-22710 - Stored XSS through autocomment system messages in Wikibase

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 8, 2026, 11:48 p.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

5.3

CVSS4.0

CVE-2026-0733 - PHPGurukul Online Course Registration System manage-students.php sql injection

A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. It is possible to initiate the attack remotely. The exploit …

πŸ“… Published: Jan. 8, 2026, 11:32 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

5.3

CVSS4.0

CVE-2026-0732 - D-Link DI-8200G upgrade_filter.asp command injection

A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.

πŸ“… Published: Jan. 8, 2026, 11:32 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

6.9

CVSS4.0

CVE-2026-0731 - TOTOLINK WA1200 HTTP Request cstecgi.cgi null pointer dereference

A vulnerability has been found in TOTOLINK WA1200 5.9c.2914. The impacted element is an unknown function of the file cstecgi.cgi of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack is possible to be carried out remotely. The exploit has been disclos…

πŸ“… Published: Jan. 8, 2026, 11:02 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.

4.8

CVSS4.0

CVE-2026-0730 - PHPGurukul Staff Leave Management System SVG File adminviews.py UPDATE_STAFF cross site scripting

A flaw has been found in PHPGurukul Staff Leave Management System 1.0. The affected element is the function ADD_STAFF/UPDATE_STAFF of the file /staffleave/slms/slms/adminviews.py of the component SVG File Handler. Executing a manipulation of the argument profile_pic can lead to cross site scripting…

πŸ“… Published: Jan. 8, 2026, 10:02 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

5.1

CVSS4.0

CVE-2026-0729 - code-projects Intern Membership Management System add_activity.php sql injection

A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_activity.php. Performing a manipulation of the argument Title results in sql injection. Remote exploitation of the attack is possible. The exploit is …

πŸ“… Published: Jan. 8, 2026, 9:32 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.
Total resulsts: 348401
Page 2141 of 34,841
Β« previous page Β» next page
Filters