8.1

CVSS3.1

CVE-2026-22595 - Ghost has Staff Token permission bypass

Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's handling of Staff Token authentication allowed certain endpoints to be accessed that were only intended to be accessible via Staff Session authentication. External …

πŸ“… Published: Jan. 10, 2026, 2:57 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

8.1

CVSS3.1

CVE-2026-22594 - Ghost has Staff 2FA bypass

Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerability in Ghost's 2FA mechanism allows staff users to skip email 2FA. This issue has been patched in versions 5.130.6 and 6.11.0.

πŸ“… Published: Jan. 10, 2026, 2:56 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

6.5

CVSS3.1

CVE-2026-22030 - React Router has CSRF issue in Action/Server Action Request Processing

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when us…

πŸ“… Published: Jan. 10, 2026, 2:42 a.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.

8

CVSS3.1

CVE-2026-22029 - React Router vulnerable to XSS via Open Redirects

React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs…

πŸ“… Published: Jan. 10, 2026, 2:42 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

8.2

CVSS3.1

CVE-2026-21884 - React Router SSR XSS in ScrollRestoration

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arb…

πŸ“… Published: Jan. 10, 2026, 2:41 a.m. πŸ”„ Last Modified: April 18, 2026, 7:15 a.m.

9.1

CVSS3.1

CVE-2025-61686 - React Router has Path Traversal in File Session Storage

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an …

πŸ“… Published: Jan. 10, 2026, 2:41 a.m. πŸ”„ Last Modified: March 3, 2026, 6:11 p.m.

7.6

CVSS3.1

CVE-2025-59057 - React Router has XSS Vulnerability

React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript exec…

πŸ“… Published: Jan. 10, 2026, 2:40 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:19 p.m.

6.5

CVSS3.1

CVE-2025-68470 - React Router has unexpected external redirect via untrusted paths

React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is on…

πŸ“… Published: Jan. 10, 2026, 2:39 a.m. πŸ”„ Last Modified: Jan. 30, 2026, 6:20 p.m.

8.9

CVSS4.0

CVE-2026-22612 - Fickling vulnerable to detection bypass due to "builtins" blindness

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detection bypass due to "builtins" blindness. This issue has been patched in version 0.1.7.

πŸ“… Published: Jan. 10, 2026, 1:35 a.m. πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

8.9

CVSS4.0

CVE-2026-22609 - Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fickling's static analyzer fails to flag several high-risk Python modules that can be used for arbitrary code execution. Malicious pickles importing these modules will not be detecte…

πŸ“… Published: Jan. 10, 2026, 1:35 a.m. πŸ”„ Last Modified: April 18, 2026, 4:45 p.m.
Total resulsts: 349182
Page 2204 of 34,919
Β« previous page Β» next page
Filters