7.5

CVSS3.1

CVE-2025-65518 - plesk: Plesk Obsidian: Denial of Service via crafted request to get_password.php

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected web interface to continuously reload, rendering the service uโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:08 a.m.

8.1

CVSS3.1

CVE-2025-67089 -

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands wโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 16, 2026, 9:26 p.m.

9.4

CVSS3.1

CVE-2025-68717 -

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user's โ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 2, 2026, 4:35 p.m.

9.4

CVSS3.1

CVE-2025-66916 -

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:05 a.m.

8.6

CVSS3.1

CVE-2026-0719 - Libsoup: signed to unsigned conversion error leading to stack-based buffer overflow in libsoup ntlmโ€ฆ

A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrecโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: April 18, 2026, 7:45 a.m.

8.8

CVSS3.1

CVE-2025-68719 -

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker can directly query the backup endpoint and download a full configuration archive. This archive contains sensitive files such as /etc/shadow, eโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 2, 2026, 4:28 p.m.

9.8

CVSS3.1

CVE-2025-66913 -

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than Cโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 30, 2026, 1:06 a.m.

4.8

CVSS3.1

CVE-2026-0716 - Libsoup: out-of-bounds read in libsoup websocket frame processing

A flaw was found in libsoupโ€™s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applicatiโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 a.m.

7.5

CVSS3.1

CVE-2025-50334 - technitium-dns-server: From CVEorg collector

An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting component

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 12, 2026, 6:39 p.m.

9.8

CVSS3.1

CVE-2025-61548 -

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterizatiโ€ฆ

๐Ÿ“… Published: Jan. 8, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 10, 2026, 6:16 p.m.
Total resulsts: 348395
Page 2158 of 34,840
ยซ previous page ยป next page
Filters