9.3

CVSS4.0

CVE-2026-22799 - emlog Arbitrary File Upload Vulnerability

Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers (with a valid API key…

πŸ“… Published: Jan. 12, 2026, 10:05 p.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

5.9

CVSS3.1

CVE-2026-22798 - hermes's raw options logging may disclose secrets passed in via subcommand options argument

hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via he…

πŸ“… Published: Jan. 12, 2026, 10 p.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

9.7

CVSS3.1

CVE-2026-22794 - Account Takeover Vulnerability in Appsmith

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generat…

πŸ“… Published: Jan. 12, 2026, 9:54 p.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

5.4

CVSS3.1

CVE-2026-22789 - WebErpMesv2 has a File Upload Validation Bypass Leading to RCE

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, WebErpMesv2 contains a file upload validation bypass vulnerability in multiple controllers that allows authenticated users to upload arbitrary files, including PHP scripts, leading to Remote Cod…

πŸ“… Published: Jan. 12, 2026, 9:52 p.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

8.2

CVSS3.1

CVE-2026-22788 - WebErpMesv2 allows unauthenticated API Access

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote attacker can read business-critical data including companies, qu…

πŸ“… Published: Jan. 12, 2026, 9:40 p.m. πŸ”„ Last Modified: April 18, 2026, 7 a.m.

9.3

CVSS4.0

CVE-2025-12420 - Unauthenticated Privilege Escalation in ServiceNow AI Platform

A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update …

πŸ“… Published: Jan. 12, 2026, 9:29 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

7.3

CVSS4.0

CVE-2026-22786 - Gin-vue-admin has arbitrary file upload vulnerability caused by path traversal

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint resume upload functionality. Attacker can upload any files on any directory. In the breakpoint_continue.go file, the MakeFile function accepts a fileName…

πŸ“… Published: Jan. 12, 2026, 9:09 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

5.8

CVSS3.1

CVE-2026-22772 - Fulcio vulnerable to Server-Side Request Forgery (SSRF) via MetaIssuer Regex Bypass

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.5, Fulcio's metaRegex() function uses unanchored regex, allowing attackers to bypass MetaIssuer URL validation and trigger SSRF to arbitrary internal services. Since the SSRF …

πŸ“… Published: Jan. 12, 2026, 8:58 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.

0.0

CVE-2026-0866 -

After the publication of the PoC by the researcher and further analysis, we have determined that this issue does not constitute a valid vulnerability. The technique described is an obfuscation method and does not bypass or impact any implicit or explicit security controls.

πŸ“… Published: Jan. 12, 2026, 7:26 p.m. πŸ”„ Last Modified: March 18, 2026, 8:16 p.m.

9.3

CVSS4.0

CVE-2026-22785 - orval MCP client is vulnerable to a code injection attack.

orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation logic relies on string manipulation that incorporates the summary field from the OpenAPI specification without proper validation or escaping. This allo…

πŸ“… Published: Jan. 12, 2026, 6:43 p.m. πŸ”„ Last Modified: April 18, 2026, 4:30 p.m.
Total resulsts: 349182
Page 2190 of 34,919
Β« previous page Β» next page
Filters