9.1

CVSS3.1

CVE-2026-23520 - Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run…

πŸ“… Published: Jan. 15, 2026, 7:20 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

4.1

CVSS3.1

CVE-2026-23766 - istio: From CVEorg collector

Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."

πŸ“… Published: Jan. 15, 2026, 7:18 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.9

CVSS4.0

CVE-2026-23519 - RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (…

πŸ“… Published: Jan. 15, 2026, 7:13 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:59 p.m.

5.3

CVSS3.1

CVE-2026-23511 - ZITADEL has a user enumeration vulnerability in Login UIs

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and …

πŸ“… Published: Jan. 15, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 4:44 p.m.

7.5

CVSS3.1

CVE-2026-22775 - devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

πŸ“… Published: Jan. 15, 2026, 6:59 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:29 p.m.

7.5

CVSS3.1

CVE-2026-22774 - devalue vulnerable to denial of service due to memory exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

πŸ“… Published: Jan. 15, 2026, 6:53 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:28 p.m.

6.6

CVSS4.0

CVE-2026-0227 - PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

πŸ“… Published: Jan. 15, 2026, 6:45 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 11:36 p.m.

7.1

CVSS3.1

CVE-2026-22249 - Docmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability …

πŸ“… Published: Jan. 15, 2026, 6:43 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 3:44 p.m.

8.2

CVSS4.0

CVE-2026-22803 - SvelteKit has a memory amplification DoS in Remote Functions binary form deserializer

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote function uses a binary data format containing a representation of submitted form data. A specially-crafted payload can cause the server to allocate a…

πŸ“… Published: Jan. 15, 2026, 6:37 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:34 p.m.

8.4

CVSS4.0

CVE-2025-67647 - SvelteKit Denial of service and possible SSRF when using prerendering

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability results in a DoS whe…

πŸ“… Published: Jan. 15, 2026, 6:33 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 8:37 p.m.
Total resulsts: 330353
Page 242 of 33,036
Β« previous page Β» next page
Filters