6.9

CVSS4.0

CVE-2026-1133 - Yonyou KSOA HTTP GET Parameter folder.jsp sql injection

A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. The attack can be launched remotely. The exploit has b…

πŸ“… Published: Jan. 19, 2026, 2:02 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:27 p.m.

6.9

CVSS4.0

CVE-2026-1132 - Yonyou KSOA HTTP GET Parameter edit_folder.jsp sql injection

A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument folderid results in sql injection. The attack can be initiated remotely. The exploit has …

πŸ“… Published: Jan. 19, 2026, 1:32 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:30 p.m.

6.9

CVSS4.0

CVE-2026-1131 - Yonyou KSOA HTTP GET Parameter save_catalog.jsp sql injection

A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The exploit has been di…

πŸ“… Published: Jan. 19, 2026, 1:02 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:32 p.m.

6.9

CVSS4.0

CVE-2026-1130 - Yonyou KSOA HTTP GET Parameter worksadd_plan.jsp sql injection

A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been …

πŸ“… Published: Jan. 19, 2026, 12:32 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:34 p.m.

6.9

CVSS4.0

CVE-2026-1129 - Yonyou KSOA HTTP GET Parameter worksadd.jsp sql injection

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public …

πŸ“… Published: Jan. 19, 2026, 12:02 a.m. πŸ”„ Last Modified: Jan. 20, 2026, 3:36 p.m.

5.8

CVSS3.1

CVE-2026-1180 - Org.keycloak.protocol.oidc: blind server-side request forgery (ssrf) in keycloak oidc dynamic clien…

A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the …

πŸ“… Published: Jan. 19, 2026, midnight πŸ”„ Last Modified: Jan. 21, 2026, 5:52 a.m.

9.9

CVSS3.1

CVE-2026-22797 - keystonemiddleware: From CVEorg collector

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged …

πŸ“… Published: Jan. 19, 2026, midnight πŸ”„ Last Modified: Jan. 26, 2026, 3:05 p.m.

6.9

CVSS4.0

CVE-2025-15539 - Open5GS sgwc s11-handler.c sgwc_s11_handle_downlink_data_notification_ack denial of service

A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notification_ack of the file src/sgwc/s11-handler.c of the component sgwc. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly di…

πŸ“… Published: Jan. 18, 2026, 11:32 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 4:37 p.m.

5.3

CVSS3.1

CVE-2026-23829 - Mailpit has SMTP Header Injection via Regex Bypass

Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existin…

πŸ“… Published: Jan. 18, 2026, 11:23 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 8:08 p.m.

4.8

CVSS4.0

CVE-2025-15538 - Open Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be…

πŸ“… Published: Jan. 18, 2026, 11:02 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 4:39 p.m.
Total resulsts: 331146
Page 290 of 33,115
Β« previous page Β» next page
Filters