5.3

CVSS4.0

CVE-2025-7048 - On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can …

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

πŸ“… Published: Jan. 6, 2026, 7:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2026-21491 - iccDEV has unicode buffer overflow in CIccTagTextDescription

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It r…

πŸ“… Published: Jan. 6, 2026, 7:07 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

6.1

CVSS3.1

CVE-2026-21490 - iccDEV has heap buffer overflow in CIccTagLut16::Validate()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It r…

πŸ“… Published: Jan. 6, 2026, 7:04 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 p.m.

5.3

CVSS4.0

CVE-2026-0641 - TOTOLINK WA300 cstecgi.cgi sub_401510 command injection

A security vulnerability has been detected in TOTOLINK WA300 5.2cu.7112_B20190227. This vulnerability affects the function sub_401510 of the file cstecgi.cgi. The manipulation of the argument UPLOAD_FILENAME leads to command injection. The attack may be initiated remotely. The exploit has been disc…

πŸ“… Published: Jan. 6, 2026, 7:02 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 p.m.

6.1

CVSS3.1

CVE-2026-21494 - iccDEV has heap buffer overflow in CIccTagLut8::Validate()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. A vulnerability present in versions prior to 2.3.1.2 affects users of the iccDEV library who process ICC color profiles. It r…

πŸ“… Published: Jan. 6, 2026, 7 p.m. πŸ”„ Last Modified: April 18, 2026, 8:15 a.m.

5.1

CVSS4.0

CVE-2025-15382 - Client SCP Request Triggers Buffer Overread by 1 Byte

A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.

πŸ“… Published: Jan. 6, 2026, 5:43 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:57 p.m.

8.1

CVSS3.1

CVE-2025-32304 - WordPress WPCHURCH plugin <= 2.7.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local File Inclusion.This issue affects WPCHURCH: from n/a through 2.7.0.

πŸ“… Published: Jan. 6, 2026, 5:34 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

9.4

CVSS4.0

CVE-2025-14942 - Authentication Bypass

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must upda…

πŸ“… Published: Jan. 6, 2026, 5:26 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:53 p.m.

9.8

CVSS3.1

CVE-2025-39477 - WordPress InWave Jobs Plugin <= 3.5.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.

πŸ“… Published: Jan. 6, 2026, 4:54 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

6.5

CVSS3.1

CVE-2024-31088 - WordPress AdsPlace'r – Ad Manager, Inserter, AdSense Ads plugin <= 1.1.5 - Cross Site Scripting (XS…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru AdsPlace'r – Ad Manager, Inserter, AdSense Ads allows DOM-Based XSS.This issue affects AdsPlace'r – Ad Manager, Inserter, AdSense Ads: from n/a through 1.1.5.

πŸ“… Published: Jan. 6, 2026, 4:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348147
Page 2163 of 34,815
Β« previous page Β» next page
Filters