6.6

CVSS3.1

CVE-2026-25749 - Heap Overflow in Vim

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags,…

📅 Published: Feb. 6, 2026, 10:43 p.m. 🔄 Last Modified: Feb. 6, 2026, 10:43 p.m.

7.5

CVSS3.1

CVE-2026-25644 - DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade

DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.

📅 Published: Feb. 6, 2026, 10:40 p.m. 🔄 Last Modified: Feb. 6, 2026, 10:40 p.m.

7.7

CVSS4.0

CVE-2026-25757 - Unauthenticated Spree Commerce users can view completed guest orders by Order ID

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers). This is…

📅 Published: Feb. 6, 2026, 10:37 p.m. 🔄 Last Modified: Feb. 6, 2026, 11:15 p.m.

8.7

CVSS4.0

CVE-2026-2070 - UTT 进取 520W formPolicyRouteConf strcpy buffer overflow

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public an…

📅 Published: Feb. 6, 2026, 10:32 p.m. 🔄 Last Modified: Feb. 6, 2026, 11:15 p.m.

9.4

CVSS4.0

CVE-2026-25763 - Command Injection on OpenProject repositories leads to Remote Code Execution

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest changes” view via git log. By su…

📅 Published: Feb. 6, 2026, 10:10 p.m. 🔄 Last Modified: Feb. 6, 2026, 10:10 p.m.

3.5

CVSS3.1

CVE-2026-25764 - OpenProject vulnerable to Stored HTML injection

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The application does not escape HTML tags, an attacker with administrator privileges can create a work pack…

📅 Published: Feb. 6, 2026, 10:10 p.m. 🔄 Last Modified: Feb. 6, 2026, 10:10 p.m.

4.8

CVSS4.0

CVE-2026-2069 - ggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflow

A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes stack-based buffer overflow. The attack needs to be launched locally. The explo…

📅 Published: Feb. 6, 2026, 10:02 p.m. 🔄 Last Modified: Feb. 6, 2026, 10:02 p.m.

9.9

CVSS4.0

CVE-2026-1731 - Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access…

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the c…

📅 Published: Feb. 6, 2026, 9:49 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:49 p.m.

9.1

CVSS4.0

CVE-2026-1727 - Information Disclosure via Bucket Squatting in Google Cloud Agentspace.

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attack…

📅 Published: Feb. 6, 2026, 9:44 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:44 p.m.

6.5

CVSS3.1

CVE-2026-25760 - Website Path Traversal / Arbitrary File Read (Authenticated) in Sliver

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.6.11, a path traversal in the website content subsystem lets an authenticated operator read arbitrary files on the Sliver server host. This is an authenticated path traversal / arbitrary file read issue, and…

📅 Published: Feb. 6, 2026, 9:32 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:32 p.m.
Total resulsts: 331487
Page 5 of 33,149
« previous page » next page
Filters