5.3

CVSS3.1

CVE-2025-67279 -

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:32 p.m.

6.5

CVSS3.1

CVE-2026-0665 - Qemu-kvm: heap off-by-one in kvm xen physdevop_map_pirq

An off-by-one error was found in QEMU's KVM Xen guest support. A malicious guest could use this flaw to trigger out-of-bounds heap accesses in the QEMU process via the emulated Xen physdev hypercall interface, leading to a denial of service or potential memory corruption.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6 p.m.

9.8

CVSS3.1

CVE-2025-69542 -

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP clie…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 7:48 p.m.

6.5

CVSS3.1

CVE-2025-66715 -

A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:44 p.m.

5.4

CVSS3.1

CVE-2025-67280 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and access sensitive data of another user.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:33 p.m.

6.5

CVSS3.1

CVE-2025-67810 -

In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST request to read arbitrary files from the server filesystem. Fixed in 1.47.4 (#7254) and further versions.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 7:45 p.m.

2.3

CVSS4.0

CVE-2026-22714 - i18n XSS, DoS and config SQLI in Monaco

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Monaco Skin allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Monaco Skin: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 8, 2026, 11:56 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

2.3

CVSS4.0

CVE-2026-22710 - Stored XSS through autocomment system messages in Wikibase

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Wikibase Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 8, 2026, 11:48 p.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

5.3

CVSS4.0

CVE-2026-0733 - PHPGurukul Online Course Registration System manage-students.php sql injection

A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. It is possible to initiate the attack remotely. The exploit …

πŸ“… Published: Jan. 8, 2026, 11:32 p.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

5.3

CVSS4.0

CVE-2026-0732 - D-Link DI-8200G upgrade_filter.asp command injection

A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.

πŸ“… Published: Jan. 8, 2026, 11:32 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 a.m.
Total resulsts: 348484
Page 2149 of 34,849
Β« previous page Β» next page
Filters