9.4

CVSS4.0

CVE-2025-59158 - Coolify has Stored XSS in Project Name

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges (e.g…

πŸ“… Published: Jan. 5, 2026, 5:44 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 3:08 p.m.

10

CVSS3.1

CVE-2025-59157 - Coolify has Git Repository RCE

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly sanitized, allowing attackers to inject arbitrary sh…

πŸ“… Published: Jan. 5, 2026, 5:41 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 3:02 p.m.

9.4

CVSS4.0

CVE-2025-59156 - Coolify has Docker Compose Injection issue

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to inject arbitrary Docker…

πŸ“… Published: Jan. 5, 2026, 5:39 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 3:03 p.m.

8.8

CVSS3.1

CVE-2025-55204 - muffon has One-click Remote Code Execution via XSS and Custom URL Handling

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or cl…

πŸ“… Published: Jan. 5, 2026, 5:37 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:11 p.m.

5.3

CVSS4.0

CVE-2025-10933 - Silicon Labs Z-Wave Protocol Controller Integer underflow vulnerability leads to out of bounds read

An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.

πŸ“… Published: Jan. 5, 2026, 5:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS3.1

CVE-2025-39484 - WordPress Entrada Theme <= 5.7.7 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.

πŸ“… Published: Jan. 5, 2026, 4:53 p.m. πŸ”„ Last Modified: April 28, 2026, 7:32 p.m.

6.5

CVSS3.1

CVE-2025-39497 - WordPress Dokan Pro plugin <= 3.14.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan Dokan Pro allows Stored XSS.This issue affects Dokan Pro: from n/a through 3.14.5.

πŸ“… Published: Jan. 5, 2026, 4:51 p.m. πŸ”„ Last Modified: April 28, 2026, 7:32 p.m.

6.5

CVSS3.1

CVE-2025-39561 - WordPress LoginWP - Pro Plugin <= 4.0.8.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in Marketing Fire, LLC LoginWP - Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LoginWP - Pro: from n/a through 4.0.8.5.

πŸ“… Published: Jan. 5, 2026, 4:50 p.m. πŸ”„ Last Modified: April 28, 2026, 7:32 p.m.

5.3

CVSS3.1

CVE-2026-21635 - Improper Access Control Allowing Wi‑Fi AutoLink on Ethernet‑Only Adopted Devices

An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet.

πŸ“… Published: Jan. 5, 2026, 4:47 p.m. πŸ”„ Last Modified: April 18, 2026, 8:30 a.m.

6.5

CVSS3.1

CVE-2026-21634 - Buffer Overflow in UniFi Protect Discovery Protocol Causes Application Restart

A malicious actor with access to the adjacent network could overflow the UniFi Protect Application (Version 6.1.79 and earlier) discovery protocol causing it to restart. Affected Products: UniFi Protect Application (Version 6.1.79 and earlier). Mitigation: Update your UniFi Protect Appl…

πŸ“… Published: Jan. 5, 2026, 4:47 p.m. πŸ”„ Last Modified: April 18, 2026, 5 p.m.
Total resulsts: 349182
Page 2285 of 34,919
Β« previous page Β» next page
Filters