7.2

CVSS3.1

CVE-2025-66648 - `vega-functions` vulnerable to Cross-site Scripting via `setdata` function

vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites that allow users to supply untrusted user input, malicious use of an internal function (not part of the public API) could be used to run unintentional javascript (XSS). This issue isโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:33 p.m. ๐Ÿ”„ Last Modified: Feb. 5, 2026, 9:27 p.m.

8.1

CVSS3.1

CVE-2025-65110 - Vega Cross-Site Scripting (XSS) via expression abusing vlSelectionTuples function array map calls iโ€ฆ

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Prior to versions 6.1.2 and 5.6.3, applications meeting two conditions are at risk of arbitrary JavaScript code execution, even if "safe mode" expressionInterpreter is used. Fiโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:22 p.m. ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:16 a.m.

9.3

CVSS4.0

CVE-2026-0625 - D-Link DSL/DIR/DNS Command Injection via DNS Configuration Endpoint

Multiple D-Link DSL/DIR/DNS devices contain an authentication bypass and improper access control vulnerability in the dnscfg.cgi endpoint that allows an unauthenticated attacker to access DNS configuration functionality. By directly requesting this endpoint, an attacker can modify the deviceโ€™s DNS โ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:14 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:30 a.m.

7.9

CVSS3.1

CVE-2025-61916 - Spinnaker vulnerable to SSRF due to improper restrictions on http from user input

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via โ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 9:14 p.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 7:19 p.m.

8.7

CVSS4.0

CVE-2026-0621 - MCP TypeScript SDK UriTemplate Exploded Array Pattern ReDoS

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated regular expression used during URI matching contains nested quโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 8:57 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:30 a.m.

8.5

CVSS4.0

CVE-2025-64425 - Coolify has host header injection in forgot password

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the request to a malicious value. The victim will receivโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 8:49 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:36 p.m.

9.4

CVSS4.0

CVE-2025-64424 - Colify has command injection vulnerability in project git source

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowing a low privileged user (member) to execute systโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 8:45 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:37 p.m.

7.7

CVSS4.0

CVE-2025-64423 - Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. When they use the link before the legitimate recipieโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 8:41 p.m. ๐Ÿ”„ Last Modified: Jan. 9, 2026, 4:10 p.m.

6.9

CVSS4.0

CVE-2026-0605 - code-projects Online Music Site login.php sql injection

A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has โ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 8:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:30 a.m.

5.5

CVSS4.0

CVE-2025-64422 - Rate-limit bypass on login via X-Forwarded-Host header

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimiteโ€ฆ

๐Ÿ“… Published: Jan. 5, 2026, 8:29 p.m. ๐Ÿ”„ Last Modified: Jan. 12, 2026, 2:23 p.m.
Total resulsts: 347837
Page 2149 of 34,784
ยซ previous page ยป next page
Filters