8

CVSS4.0

CVE-2026-25804 - Antrea has invalid enforcement order for network policy rules caused by integer overflow

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assignment system has a uint16 arithmetic overflow bug that causes incorrect OpenFlow priority calculations when handling a large numbers of policies withโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:58 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:15 p.m.

7.6

CVSS4.0

CVE-2026-25793 - Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability

Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration), it is possible to evade a blocklist entry created against the fingerprint of a certificate by using ECDSA Signature Malleability to use a copy of thโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:55 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:15 p.m.

9.8

CVSS3.1

CVE-2026-25803 - 3DP-MANAGER Uses Hard-coded Credentials

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full admโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:15 p.m.

7.5

CVSS3.1

CVE-2026-25762 - AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler durโ€ฆ

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multipart parser may accumulate an unbounded amount of data in memโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 10:48 p.m.

7.2

CVSS3.1

CVE-2026-25754 - AdonisJS multipart body parsing has Prototype Pollution issue

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-nexโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:48 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 10:48 p.m.

6.6

CVSS3.1

CVE-2026-25749 - Heap Overflow in Vim

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags,โ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:43 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 10:43 p.m.

7.5

CVSS3.1

CVE-2026-25644 - DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade

DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.

๐Ÿ“… Published: Feb. 6, 2026, 10:40 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 10:40 p.m.

7.7

CVSS4.0

CVE-2026-25757 - Unauthenticated Spree Commerce users can view completed guest orders by Order ID

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers). This isโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:37 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:15 p.m.

8.7

CVSS4.0

CVE-2026-2070 - UTT ่ฟ›ๅ– 520W formPolicyRouteConf strcpy buffer overflow

A vulnerability has been found in UTT ่ฟ›ๅ– 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public anโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:32 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:15 p.m.

9.4

CVSS4.0

CVE-2026-25763 - Command Injection on OpenProject repositories leads to Remote Code Execution

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProjectโ€™s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the โ€œlatest changesโ€ view via git log. By suโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 10:10 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 10:10 p.m.
Total resulsts: 331502
Page 6 of 33,151
ยซ previous page ยป next page
Filters