7.2

CVSS3.1

CVE-2025-70397 -

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: Feb. 19, 2026, 6:24 p.m.

9.9

CVSS3.1

CVE-2025-70830 -

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.9

CVSS4.0

CVE-2025-32355 -

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:34 a.m.

8.8

CVSS3.1

CVE-2026-26736 - Stack‑Based Buffer Overflow in TOTOLINK A3002RU_V3 IPv6 Setup

TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7 p.m.

9.4

CVSS4.0

CVE-2025-59793 -

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This all…

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:34 a.m.

8.8

CVSS3.1

CVE-2025-70828 -

An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:33 a.m.

8.7

CVSS3.1

CVE-2025-67905 -

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an a…

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-70829 -

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 1:17 p.m.

8

CVSS3.1

CVE-2026-26731 - Stack-based Buffer Overflow in TOTOLINK A3002RU Router Firmware via Routernamer Parameter

TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 7 a.m.

7.6

CVSS3.1

CVE-2025-67102 -

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:34 a.m.
Total resulsts: 346582
Page 1355 of 34,659
Β« previous page Β» next page
Filters