5.3

CVSS3.1

CVE-2026-23829 - Mailpit has SMTP Header Injection via Regex Bypass

Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existin…

📅 Published: Jan. 18, 2026, 11:23 p.m. 🔄 Last Modified: Jan. 20, 2026, 8:08 p.m.

4.8

CVSS4.0

CVE-2025-15538 - Open Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be…

📅 Published: Jan. 18, 2026, 11:02 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:39 p.m.

6.4

CVSS3.1

CVE-2026-23733 - Lobe Chat has Cross-Site Scripting (XSS) issue that may escalate to Remote Code Execution (RCE)

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Executi…

📅 Published: Jan. 18, 2026, 10:56 p.m. 🔄 Last Modified: Jan. 20, 2026, 8:06 p.m.

7.7

CVSS4.0

CVE-2026-23644 - esm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packag…

esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in a malicious tar file…

📅 Published: Jan. 18, 2026, 10:49 p.m. 🔄 Last Modified: Jan. 20, 2026, 8:06 p.m.

6.8

CVSS3.1

CVE-2026-23626 - Kimai Vulnerable to Authenticated Server-Side Template Injection (SSTI)

Kimai is a web-based multi-user time-tracking application. Prior to version 2.46.0, Kimai's export functionality uses a Twig sandbox with an overly permissive security policy (`DefaultPolicy`) that allows arbitrary method calls on objects available in the template context. An authenticated user wit…

📅 Published: Jan. 18, 2026, 10:45 p.m. 🔄 Last Modified: Jan. 20, 2026, 8:07 p.m.

6.4

CVSS3.1

CVE-2026-23525 - 1panel App Store vulnerable to Cross-site Scripting

1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel App Store when viewing application details. Malicious scripts can execute in the context of the user’s browser, potentially compromising session data…

📅 Published: Jan. 18, 2026, 10:10 p.m. 🔄 Last Modified: Jan. 20, 2026, 8:07 p.m.

5.3

CVSS4.0

CVE-2026-1126 - lwj flow SVG File FormResource.java uploadFile unrestricted upload

A security vulnerability has been detected in lwj flow up to a3d2fe8133db9d3b50fda4f66f68634640344641. This affects the function uploadFile of the file \flow-master\flow-front-rest\src\main\java\com\dragon\flow\web\resource\flow\FormResource.java of the component SVG File Handler. The manipulation …

📅 Published: Jan. 18, 2026, 4:32 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:41 p.m.

6.9

CVSS4.0

CVE-2026-1125 - D-Link DIR-823X set_wifidog_settings sub_412E7C command injection

A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made avai…

📅 Published: Jan. 18, 2026, 4:02 p.m. 🔄 Last Modified: Jan. 30, 2026, 4:49 p.m.

8.5

CVSS3.1

CVE-2026-0863 - Sandbox escape in n8n Python task runner allows for arbitrary code execution on the underlying host.

Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code block by an authenticated user with basic permission…

📅 Published: Jan. 18, 2026, 3:37 p.m. 🔄 Last Modified: Jan. 23, 2026, 6:16 p.m.

6.9

CVSS4.0

CVE-2026-1124 - Yonyou KSOA HTTP GET Parameter work_report.jsp sql injection

A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the at…

📅 Published: Jan. 18, 2026, 3:32 p.m. 🔄 Last Modified: Jan. 20, 2026, 4:43 p.m.
Total resulsts: 331148
Page 291 of 33,115
« previous page » next page
Filters