6.9

CVSS4.0

CVE-2025-66002 - Local users can perform arbitrary unmounts via smb4k mount helper due to lack of input validation

An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability allows local users ton perform arbitrary unmounts via smb4k mount helper

πŸ“… Published: Jan. 8, 2026, 2:25 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

7.2

CVSS4.0

CVE-2026-22028 - Preact has JSON VNode Injection issue

Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON payloads are assumed to …

πŸ“… Published: Jan. 8, 2026, 2:16 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:58 p.m.

2.7

CVSS4.0

CVE-2026-21895 - rsa crate has potential panic on a prime being equal to 1

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.

πŸ“… Published: Jan. 8, 2026, 2:06 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

5.3

CVSS3.1

CVE-2026-21892 - Parsl Monitoring Visualization Vulnerable to SQL Injection

Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python % operator) with user-supplied input (workflow_id) directly from URL rou…

πŸ“… Published: Jan. 8, 2026, 2:02 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

9.4

CVSS3.1

CVE-2026-21891 - ZimaOS has Authentication Bypass via System-Level Username

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a know…

πŸ“… Published: Jan. 8, 2026, 2 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:13 p.m.

6.5

CVSS3.1

CVE-2026-21885 - Miniflux Media Proxy SSRF via /proxy endpoint allows access to internal network resources

Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SSRF). An authenticated user can cause Miniflux to generate a signed proxy URL for attacker-chosen med…

πŸ“… Published: Jan. 8, 2026, 1:57 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 4:55 p.m.

9.3

CVSS3.1

CVE-2026-21876 - OWASP CRS has multipart bypass using multiple content-type parts

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a co…

πŸ“… Published: Jan. 8, 2026, 1:55 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

5.9

CVSS4.0

CVE-2025-8307 - Recoverable passwords in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. Passwords of all users are stored in a database in an encoded format. An attacker in possession of these encoded passwords is able to decode them by using an algorithm embedd…

πŸ“… Published: Jan. 8, 2026, 1:43 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

5.1

CVSS4.0

CVE-2025-8306 - Improper Access Control in Asseco Infomedica Plus

Asseco InfoMedica is a comprehensive solution used to manage both administrative and medical tasks in the healthcare sector. A low privileged user is able to obtain encoded passwords of all other accounts (including main administrator) due to lack of granularity in access control.Β  Chained exploita…

πŸ“… Published: Jan. 8, 2026, 1:43 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

7.5

CVSS3.1

CVE-2025-69260 -

A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.

πŸ“… Published: Jan. 8, 2026, 12:50 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.
Total resulsts: 327160
Page 43 of 32,716
Β« previous page Β» next page
Filters