7.3

CVSS4.0

CVE-2025-68619 - Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name exists in the npm registry as a known plugin …

πŸ“… Published: Jan. 1, 2026, 6:35 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 5:57 p.m.

6.9

CVSS4.0

CVE-2025-15409 - code-projects Online Guitar Store Delete_product.php sql injection

A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql injection. The attack may be performed from remote. The exploit…

πŸ“… Published: Jan. 1, 2026, 6:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

7.5

CVSS3.1

CVE-2025-55065 -

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

πŸ“… Published: Jan. 1, 2026, 6:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-68620 - Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-based request enumeration with unauthenticated p…

πŸ“… Published: Jan. 1, 2026, 6:29 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 5:56 p.m.

5.3

CVSS3.1

CVE-2025-68273 - Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed…

πŸ“… Published: Jan. 1, 2026, 6:21 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 5:58 p.m.

7.5

CVSS3.1

CVE-2025-68272 - Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a "Ja…

πŸ“… Published: Jan. 1, 2026, 6:08 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 6:23 p.m.

2

CVSS4.0

CVE-2026-21437 - eopkg vulnerable to package file list integrity bypass

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by `lseopkg` an…

πŸ“… Published: Jan. 1, 2026, 6:06 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

5.8

CVSS4.0

CVE-2026-21436 - eopkg has Path Traversal: '../filedir' vulnerability

eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape the directory set by `--destdir`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be installed in the path given…

πŸ“… Published: Jan. 1, 2026, 6:03 p.m. πŸ”„ Last Modified: April 18, 2026, 8:45 a.m.

6.9

CVSS4.0

CVE-2025-15408 - code-projects Online Guitar Store Create_product.php sql injection

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possible to be carried out remotely. The exploit has been made publi…

πŸ“… Published: Jan. 1, 2026, 6:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

9.7

CVSS3.1

CVE-2025-66398 - Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Re…

πŸ“… Published: Jan. 1, 2026, 6 p.m. πŸ”„ Last Modified: Jan. 6, 2026, 6:34 p.m.
Total resulsts: 349182
Page 2312 of 34,919
Β« previous page Β» next page
Filters