8.9

CVSS4.0

CVE-2026-21441 - urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming …

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `C…

📅 Published: Jan. 7, 2026, 10:09 p.m. 🔄 Last Modified: Jan. 8, 2026, 8:08 p.m.

8.8

CVSS3.1

CVE-2026-22047 - iccDEV has heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cpp

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in `SIccCalcOp::Describe()` at `IccProfLib/IccMpeCalc.cpp…

📅 Published: Jan. 7, 2026, 10:05 p.m. 🔄 Last Modified: Jan. 8, 2026, 8:15 p.m.

1.8

CVSS4.0

CVE-2025-12776 - Stored Cross-Site Scripting

The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting (XSS) attack. Proper management of this functionality helps ensure a secure and seamless user experience.  Although th…

📅 Published: Jan. 7, 2026, 10:03 p.m. 🔄 Last Modified: Jan. 8, 2026, 6:17 p.m.

8.8

CVSS3.1

CVE-2026-22046 - iccDEV has heap-buffer-overflow in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.c…

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow vulnerability in `CIccProfileXml::ParseBasic()` at `IccXML/IccLibXML/Ic…

📅 Published: Jan. 7, 2026, 10:02 p.m. 🔄 Last Modified: Jan. 8, 2026, 7:15 p.m.

8.8

CVSS3.1

CVE-2026-21693 - iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccSegmentedCurveXml::ToXml()` at `IccXML/IccLibXML/IccMpe…

📅 Published: Jan. 7, 2026, 9:58 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:29 p.m.

8.8

CVSS3.1

CVE-2026-21692 - iccDEV has Type Confusion in ToXmlCurve() at IccXML/IccLibXML/IccMpeXml.cpp

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `ToXmlCurve()` at `IccXML/IccLibXML/IccMpeXml.cpp`. This vul…

📅 Published: Jan. 7, 2026, 9:56 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:27 p.m.

8.8

CVSS3.1

CVE-2025-69264 - pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDepen…

📅 Published: Jan. 7, 2026, 9:53 p.m. 🔄 Last Modified: Jan. 12, 2026, 9:53 p.m.

5.4

CVSS3.1

CVE-2026-21691 - iccDEV has Type Confusion in CIccTag:IsTypeCompressed()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccTag:IsTypeCompressed()`. This vulnerability affects use…

📅 Published: Jan. 7, 2026, 9:53 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:26 p.m.

6.3

CVSS3.1

CVE-2026-21690 - iccDEV has Type Confusion in CIccTagXmlTagData::ToXml()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccTagXmlTagData::ToXml()`. This vulnerability affects use…

📅 Published: Jan. 7, 2026, 9:50 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:26 p.m.

6.5

CVSS3.1

CVE-2026-21689 - iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccProfileXml::ParseBasic()` at `IccXML/IccLibXML/IccProfi…

📅 Published: Jan. 7, 2026, 9:46 p.m. 🔄 Last Modified: Jan. 12, 2026, 6:25 p.m.
Total resulsts: 327160
Page 60 of 32,716
« previous page » next page
Filters