10

CVSS4.0

CVE-2026-22781 - TinyWeb CGI Command Injection

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An un…

πŸ“… Published: Jan. 12, 2026, 6:23 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:23 p.m.

8.7

CVSS4.0

CVE-2026-22776 - cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library validates the payload…

πŸ“… Published: Jan. 12, 2026, 6:18 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:18 p.m.

8.8

CVSS3.1

CVE-2026-22771 - Envoy Extension Policy lua scripts injection causes arbitrary command execution

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be used to communicate…

πŸ“… Published: Jan. 12, 2026, 6:08 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:08 p.m.

9.1

CVSS3.1

CVE-2026-22252 - LibreChat MCP Stdio Remote Command Execution

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed…

πŸ“… Published: Jan. 12, 2026, 6:01 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:01 p.m.

5.3

CVSS3.1

CVE-2026-22251 - wlc may leak API keys due to an insecure API key configuration

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

πŸ“… Published: Jan. 12, 2026, 5:55 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:55 p.m.

2.5

CVSS3.1

CVE-2026-22250 - wlc can skip SSL verification

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.

πŸ“… Published: Jan. 12, 2026, 5:52 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:52 p.m.

8.6

CVSS4.0

CVE-2026-22033 - Label Studio vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via …

Label Studio is a multi-type data labeling and annotation tool. In 1.22.0 and earlier, a persistent stored cross-site scripting (XSS) vulnerability exists in the custom_hotkeys functionality of the application. An authenticated attacker (or one who can trick a user/administrator into updating their…

πŸ“… Published: Jan. 12, 2026, 5:47 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:47 p.m.

6.5

CVSS3.1

CVE-2025-68471 - Avahi has a reachable assertion in lookup_start

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds apart.

πŸ“… Published: Jan. 12, 2026, 5:39 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:39 p.m.

6.5

CVSS3.1

CVE-2025-68468 - Avahi has a reachable assertion in lookup_multicast_callback

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointing it to resource records with short TTLs. As soon as they ex…

πŸ“… Published: Jan. 12, 2026, 5:38 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:38 p.m.

5.5

CVSS3.1

CVE-2025-68276 - Avahi has a reachable assertion in avahi_wide_area_scan_cache

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-daemon (with wide-area disabled) by creating record browsers with the AVAHI_LOOKUP_USE_WIDE_AREA flag set via D-Bus. This …

πŸ“… Published: Jan. 12, 2026, 5:31 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 5:31 p.m.
Total resulsts: 327160
Page 9 of 32,716
Β« previous page Β» next page
Filters