7.4

CVSS4.0

CVE-2026-23622 - CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover

Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters fro…

πŸ“… Published: Jan. 15, 2026, 7:28 p.m. πŸ”„ Last Modified: Jan. 28, 2026, 5:33 p.m.

8.9

CVSS3.1

CVE-2026-23527 - Request Smuggling (TE.TE) in h3 v1

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, this heade…

πŸ“… Published: Jan. 15, 2026, 7:24 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:50 p.m.

9.1

CVSS3.1

CVE-2026-23520 - Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run…

πŸ“… Published: Jan. 15, 2026, 7:20 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

4.1

CVSS3.1

CVE-2026-23766 - istio: From CVEorg collector

Istio through 1.28.2 allows iptables rule injection for changing firewall behavior via the traffic.sidecar.istio.io/excludeInterfaces annotation. NOTE: the reporter's position is "this doesn't represent a security vulnerability (pod creators can already exclude sidecar injection entirely)."

πŸ“… Published: Jan. 15, 2026, 7:18 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

8.9

CVSS4.0

CVE-2026-23519 - RustCrypto cmov: thumbv6m-none-eabi compiler emits non-constant time assembly when using cmovnz

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (…

πŸ“… Published: Jan. 15, 2026, 7:13 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 6:59 p.m.

5.3

CVSS3.1

CVE-2026-23511 - ZITADEL has a user enumeration vulnerability in Login UIs

ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating through usernames and …

πŸ“… Published: Jan. 15, 2026, 7:09 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 4:44 p.m.

7.5

CVSS3.1

CVE-2026-22775 - devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

πŸ“… Published: Jan. 15, 2026, 6:59 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:29 p.m.

7.5

CVSS3.1

CVE-2026-22774 - devalue vulnerable to denial of service due to memory exhaustion in devalue.parse

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potentially leading to denial of service in systems that parse input …

πŸ“… Published: Jan. 15, 2026, 6:53 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:28 p.m.

6.6

CVSS4.0

CVE-2026-0227 - PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

πŸ“… Published: Jan. 15, 2026, 6:45 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 11:36 p.m.

7.1

CVSS3.1

CVE-2026-22249 - Docmost affected by an Arbitrary File Write via Zip Import Feature (ZipSlip)

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability …

πŸ“… Published: Jan. 15, 2026, 6:43 p.m. πŸ”„ Last Modified: Jan. 22, 2026, 3:44 p.m.
Total resulsts: 330385
Page 245 of 33,039
Β« previous page Β» next page
Filters