6.1

CVSS3.1

CVE-2026-25956 - Frappe Affected by XSS and Open Redirect in Sign Up

Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user signs up. This vulnerability is fixed in 14.99.14 a…

πŸ“… Published: Feb. 10, 2026, 5:39 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:41 p.m.

6.9

CVSS4.0

CVE-2026-1996 - Certain HP OfficeJet Pro Printers – Denial of Service

Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.

πŸ“… Published: Feb. 10, 2026, 5:34 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 9:52 p.m.

8.8

CVSS3.1

CVE-2026-25947 - Worklenz Boolean-Based Blind SQL Injection via Improper ORDER BY Clause Input Validation

Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered in backend SQL query construction affecting project and task management controllers, reporting and financial data endpoints, real-time socket.io handlers, and resource allocation …

πŸ“… Published: Feb. 10, 2026, 5:32 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:41 p.m.

5.3

CVSS4.0

CVE-2026-0651 - Path Traversal on TP-Link Tapo D235 and C260 via Local https

On TP-Link Tapo C260 v1, path traversal is possible due to improper handling of specific GET request paths via https, allowing local unauthenticated probing of filesystem paths. An attacker on the local network can determine whether certain files exists on the device, with no read, write or code ex…

πŸ“… Published: Feb. 10, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2026-25805 - Zed does not show Parameter Values for MCP Tool Calls. Users cannot detect tool poisoning.

Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values could be used without …

πŸ“… Published: Feb. 10, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:41 p.m.

8.7

CVSS4.0

CVE-2026-0652 - Remote Code Execution on TP-Link Tapo C260 by Guest User

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause…

πŸ“… Published: Feb. 10, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:45 p.m.

7.2

CVSS4.0

CVE-2026-0653 - Insecure Access Control on TP-Link Tapo D235 and C260

On TP-Link Tapo C260 v1, aΒ guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters wi…

πŸ“… Published: Feb. 10, 2026, 5:27 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:45 p.m.

9.3

CVSS4.0

CVE-2026-25728 - ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Condition

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability exists in ClipBucket's avatar and background image upload functionality. The application moves uploaded files to a web-accessible location before valida…

πŸ“… Published: Feb. 10, 2026, 5:12 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 3:30 p.m.

8.3

CVSS4.0

CVE-2026-25646 - LIBPNG has a heap buffer overflow in png_set_quantize

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the numbe…

πŸ“… Published: Feb. 10, 2026, 5:04 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 8:43 p.m.

7.5

CVSS3.1

CVE-2026-25577 - Emmett has an Unhandled CookieError Exception Causing Denial of Service

Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core.http.wrappers.Request does not handle CookieError exceptions when parsing malformed Cookie headers. This allows unauthenticated attackers to trigger HTTP 500 errors and cause den…

πŸ“… Published: Feb. 10, 2026, 5:01 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 9:40 a.m.
Total resulsts: 332907
Page 90 of 33,291
Β« previous page Β» next page
Filters