5.5

CVSS3.1

CVE-2026-21315 - Audition | Out-of-bounds Read (CWE-125)

Audition versions 25.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open โ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 3:20 p.m.

5.5

CVSS3.1

CVE-2026-21313 - Audition | Out-of-bounds Read (CWE-125)

Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must opeโ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 3:19 p.m.

5.5

CVSS3.1

CVE-2026-21317 - Audition | Out-of-bounds Read (CWE-125)

Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must opeโ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 3:18 p.m.

5.5

CVSS3.1

CVE-2026-21314 - Audition | Out-of-bounds Read (CWE-125)

Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must opeโ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:45 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 3:14 p.m.

9.3

CVSS4.0

CVE-2026-25993 - EverShop has a Second-Order SQL Injection in URL Rewrite Processing Derived from Category URL Keys

EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path valuesโ€”derived from the url_key stored in the databaseโ€”into SQL statements via string concatenation and passes them to execute(). As a result, if a malicโ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:43 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 9:52 p.m.

6.1

CVSS3.1

CVE-2026-25956 - Frappe Affected by XSS and Open Redirect in Sign Up

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user signs up. This vulnerability is fixed in 14.99.14 aโ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:39 p.m. ๐Ÿ”„ Last Modified: Feb. 10, 2026, 9:41 p.m.

6.9

CVSS4.0

CVE-2026-1996 - Certain HP OfficeJet Pro Printers โ€“ Denial of Service

Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.

๐Ÿ“… Published: Feb. 10, 2026, 5:34 p.m. ๐Ÿ”„ Last Modified: Feb. 11, 2026, 9:52 p.m.

8.8

CVSS3.1

CVE-2026-25947 - Worklenz Boolean-Based Blind SQL Injection via Improper ORDER BY Clause Input Validation

Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation โ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:32 p.m. ๐Ÿ”„ Last Modified: Feb. 10, 2026, 9:41 p.m.

5.3

CVSS4.0

CVE-2026-0651 - Path Traversal on TP-Link Tapo D235 and C260 via Local https

On TP-Link Tapo C260 v1, path traversal is possible due to improper handling of specific GET request paths via https, allowing local unauthenticated probing of filesystem paths. An attacker on the local network can determine whether certain files exists on the device, with no read, write or code exโ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:27 p.m. ๐Ÿ”„ Last Modified: Feb. 13, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2026-25805 - Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values could be used without โ€ฆ

๐Ÿ“… Published: Feb. 10, 2026, 5:27 p.m. ๐Ÿ”„ Last Modified: Feb. 10, 2026, 9:41 p.m.
Total resulsts: 332892
Page 88 of 33,290
ยซ previous page ยป next page
Filters