7.1

CVSS4.0

CVE-2025-14631 - Null Pointer Dereference Vulnerability in Malformed 802.11 Frame of TP-Link Archer BE400

A NULL Pointer Dereference vulnerability in TP-Link Archer BE400 V1(802.11 modules) allowsΒ  an adjacent attacker to cause a denial-of-service (DoS) by triggering a device reboot. This issue affects Archer BE400: xi 1.1.0 Build 20250710 rel.14914.

πŸ“… Published: Jan. 7, 2026, 1:04 a.m. πŸ”„ Last Modified: March 12, 2026, 7:29 p.m.

5.1

CVSS4.0

CVE-2026-0649 - invoiceninja Migration Import Import.php copy server-side request forgery

A security vulnerability has been detected in invoiceninja up to 5.12.38. The affected element is the function copy of the file /app/Jobs/Util/Import.php of the component Migration Import. The manipulation of the argument company_logo leads to server-side request forgery. It is possible to initiate…

πŸ“… Published: Jan. 7, 2026, 12:32 a.m. πŸ”„ Last Modified: April 18, 2026, 5 p.m.

2.3

CVSS4.0

CVE-2024-14020 - carboneio carbone Formatter input.js prototype pollution

A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. T…

πŸ“… Published: Jan. 7, 2026, 12:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS3.1

CVE-2025-61492 -

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 1:40 a.m.

6.5

CVSS3.1

CVE-2025-66838 -

In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files at an unrestricted rate. An attacker can exploit this behavior to rapidly upload a large volume of files, potentially leading to resource exhaustion …

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 10:06 p.m.

7.5

CVSS3.1

CVE-2025-65805 -

OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-of-service attack and potentially execute malicious code by accessing port N1 and sending an imsi string longer than 1000 to AMF.

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:12 a.m.

5.3

CVSS3.1

CVE-2026-0707 - Keycloak: keycloak authorization header parsing leading to potential security control bypass

A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard characters (such as tabs) as separators and tolerates case variations that deviate from RFC 6750 specifications.

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 8 a.m.

7.5

CVSS3.1

CVE-2025-67364 -

fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and isPathAllowed functi…

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:03 a.m.

6.1

CVSS3.1

CVE-2025-66686 -

A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the β€œHelp button url” setting within the admin panel. The injected payload is stored and executed when any authentica…

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 10:07 p.m.

7.5

CVSS3.1

CVE-2025-66786 -

OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface to launch a denial-of-service attack.

πŸ“… Published: Jan. 7, 2026, midnight πŸ”„ Last Modified: Jan. 29, 2026, 1:06 a.m.
Total resulsts: 349182
Page 2261 of 34,919
Β« previous page Β» next page
Filters