9.6

CVSS3.1

CVE-2025-12543 - Undertow-core: undertow http server fails to reject malformed host headers leading to potential cacโ€ฆ

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rโ€ฆ

๐Ÿ“… Published: Jan. 7, 2026, midnight ๐Ÿ”„ Last Modified: May 6, 2026, 2:33 p.m.

6.8

CVSS3.1

CVE-2025-66837 -

A file upload vulnerability in ARIS 10.0.23.0.3587512 allows attackers to execute arbitrary code via uploading a crafted PDF file/Malware

๐Ÿ“… Published: Jan. 7, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 21, 2026, 10:05 p.m.

7.5

CVSS3.1

CVE-2025-67366 -

@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism:โ€ฆ

๐Ÿ“… Published: Jan. 7, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2026, 1:02 a.m.

6.5

CVSS3.1

CVE-2025-61489 -

A command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands via supplying a crafted command string.

๐Ÿ“… Published: Jan. 7, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 29, 2026, 1:13 a.m.

8.8

CVSS3.1

CVE-2026-0628 - Privilege Escalation via Malicious Extension in Chrome's WebView Tag

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

๐Ÿ“… Published: Jan. 6, 2026, 11:57 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:15 a.m.

6.9

CVSS4.0

CVE-2026-0643 - projectworlds House Rental and Property Listing Signup register.php unrestricted upload

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The explโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 11:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:15 a.m.

7.8

CVSS3.1

CVE-2025-47396 - Double Free in Graphics

Memory corruption occurs when a secure application is launched on a device with insufficient memory.

๐Ÿ“… Published: Jan. 6, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 7:15 p.m.

6.5

CVSS3.1

CVE-2025-47395 - Buffer Over-read in WLAN Firmware

Transient DOS while parsing a WLAN management frame with a Vendor Specific Information Element.

๐Ÿ“… Published: Jan. 6, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 7:16 p.m.

7.8

CVSS3.1

CVE-2025-47394 - Buffer Copy Without Checking Size of Input in DSP Service

Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.

๐Ÿ“… Published: Jan. 6, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 7:19 p.m.

7.8

CVSS3.1

CVE-2025-47393 - Improper Validation of Array Index in Automotive Linux OS

Memory corruption when accessing resources in kernel driver.

๐Ÿ“… Published: Jan. 6, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: Jan. 27, 2026, 7:20 p.m.
Total resulsts: 349182
Page 2262 of 34,919
ยซ previous page ยป next page
Filters