5.9

CVSS3.1

CVE-2025-13034 - No QUIC certificate pinning with GnuTLS

When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey` with the curl tool,curl should check the public key of the server certificate to verify the peer. This check was skipped in a certain condition that would then make curl allow the connection without performing the proper …

πŸ“… Published: Jan. 8, 2026, 10 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

4.9

CVSS3.1

CVE-2026-22242 - CoreShop Vulnerable to SQL Injection via Admin Reports

CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the …

πŸ“… Published: Jan. 8, 2026, 9:59 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 4:42 p.m.

6.5

CVSS3.1

CVE-2026-21894 - n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

n8n is an open source workflow automation platform. In versions from 0.150.0 to before 2.2.2, an authentication bypass vulnerability in the Stripe Trigger node allows unauthenticated parties to trigger workflows by sending forged Stripe webhook events. The Stripe Trigger creates and stores a Stripe…

πŸ“… Published: Jan. 8, 2026, 9:56 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

5.3

CVSS3.1

CVE-2026-21874 - NiceGUI has Redis connection leak via tab storage causes service degradation

NiceGUI is a Python-based UI framework. From versions v2.10.0 to 3.4.1, an unauthenticated attacker can exhaust Redis connections by repeatedly opening and closing browser tabs on any NiceGUI application using Redis-backed storage. Connections are never released, leading to service degradation when…

πŸ“… Published: Jan. 8, 2026, 9:50 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

7.2

CVSS3.1

CVE-2026-21873 - Zero-click XSS in all NiceGUI apps which uses `ui.sub_pages`

NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the pushstate event listener used by ui.sub_pages allows an attacker to manipulate the fragment identifier of the URL, which they can do despite being cross-site, using an iframe. This issue has been …

πŸ“… Published: Jan. 8, 2026, 9:50 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

6.1

CVSS3.1

CVE-2026-21872 - NiceGUI apps are vulnerable to XSS which uses `ui.sub_pages` and render arbitrary user-provided lin…

NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the click event listener used by ui.sub_pages, combined with attacker-controlled link rendering on the page, causes XSS when the user actively clicks on the link. This issue has been patched in versio…

πŸ“… Published: Jan. 8, 2026, 9:50 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

6.1

CVSS3.1

CVE-2026-21871 - NiceGUI is vulnerable to XSS via Unescaped URL in ui.navigate.history.push() / replace()

NiceGUI is a Python-based UI framework. From versions 2.13.0 to 3.4.1, there is a XSS risk in NiceGUI when developers pass attacker-controlled strings into ui.navigate.history.push() or ui.navigate.history.replace(). These helpers are documented as History API wrappers for updating the browser URL …

πŸ“… Published: Jan. 8, 2026, 9:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 1:25 p.m.

6.4

CVSS3.1

CVE-2025-14984 - Gutenverse Form <= 2.3.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Gutenverse Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.3.2. This is due to the plugin's framework component adding SVG to the allowed MIME types via the upload_mimes filter without implementing any sanitizati…

πŸ“… Published: Jan. 8, 2026, 9:20 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

0.0

CVE-2026-0676 - WordPress Zorka theme <= 1.5.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in G5Theme Zorka zorka allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zorka: from n/a through <= 1.5.7.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:31 p.m.

0.0

CVE-2026-0675 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.
Total resulsts: 327160
Page 45 of 32,716
Β« previous page Β» next page
Filters