5.1

CVSS4.0

CVE-2019-25372 - OPNsense 19.1 Reflected XSS via diag_traceroute.php

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation in the host parameter. Attackers can submit crafted payloads through POST requests to diag_traceroute.php to execute ar…

πŸ“… Published: Feb. 15, 2026, 1:58 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25371 - OPNsense 19.1 Reflected XSS via diag_ping.php

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting insufficient input validation in the host parameter. Attackers can submit crafted POST requests to the diag_ping.php endpoint with script payloads in…

πŸ“… Published: Feb. 15, 2026, 1:58 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25370 - OPNsense 19.1 Reflected XSS via interfaces_vlan_edit.php

OPNsense 19.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input through multiple parameters. Attackers can send POST requests to interfaces_vlan_edit.php with script payloads in the tag, descr, or vlanif parameters …

πŸ“… Published: Feb. 15, 2026, 1:58 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2019-25369 - OPNsense 19.1 Stored XSS via system_advanced_sysctl.php

OPNsense 19.1 contains a stored cross-site scripting vulnerability in the system_advanced_sysctl.php endpoint that allows attackers to inject persistent malicious scripts via the tunable parameter. Attackers can submit POST requests with script payloads that are stored and executed in the context o…

πŸ“… Published: Feb. 15, 2026, 1:58 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

4.8

CVSS4.0

CVE-2019-25368 - OPNsense 19.1 Reflected XSS via diag_backup.php

OPNsense 19.1 contains multiple cross-site scripting vulnerabilities in the diag_backup.php endpoint that allow attackers to inject malicious scripts through multiple parameters including GDrive_GDriveEmail, GDrive_GDriveFolderID, GDrive_GDriveBackupCount, Nextcloud_url, Nextcloud_user, Nextcloud_p…

πŸ“… Published: Feb. 15, 2026, 1:58 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

4.8

CVSS4.0

CVE-2019-25367 - ArangoDB Community Edition 3.4.2-1 XSS via aardvark admin interface

ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScrip…

πŸ“… Published: Feb. 15, 2026, 1:58 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-2517 - Open5GS SMF types.c ogs_gtp2_parse_tft denial of service

A security flaw has been discovered in Open5GS up to 2.7.6. This vulnerability affects the function ogs_gtp2_parse_tft in the library lib/gtp/v2/types.c of the component SMF. Performing a manipulation of the argument pf[0].content.length results in denial of service. The attack is possible to be ca…

πŸ“… Published: Feb. 15, 2026, 12:32 p.m. πŸ”„ Last Modified: April 17, 2026, 7:30 p.m.

7.3

CVSS4.0

CVE-2026-2516 - Unidocs ezPDF DRM Reader/ezPDF Reader SHFOLDER.dll uncontrolled search path

A vulnerability was identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2.0/3.0.0.4. This affects an unknown part in the library SHFOLDER.dll. Such manipulation leads to uncontrolled search path. The attack needs to be performed locally. Attacks of this nature are highly complex. It is indicate…

πŸ“… Published: Feb. 15, 2026, 12:02 p.m. πŸ”„ Last Modified: April 15, 2026, 5:30 p.m.

6.4

CVSS4.0

CVE-2026-2541 - Micca KE700 Brute-force vulnerability due to low entropy

The Micca KE700 system relies on a 6-bit portion of an identifier for authentication within rolling codes, providing only 64 possible combinations. This low entropy allows an attacker to perform a brute-force attack against one component of the rolling code. Successful exploitation simplify an atta…

πŸ“… Published: Feb. 15, 2026, 11:07 a.m. πŸ”„ Last Modified: April 17, 2026, 7:30 p.m.

8.4

CVSS4.0

CVE-2026-2540 - Micca KE700 Acceptance of previously used rolling codes

The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires sending two previously captured codes in a specific sequence. As a result, the system can be forced to accept previously used (stale) rolling codes and execute a command. Success…

πŸ“… Published: Feb. 15, 2026, 11:03 a.m. πŸ”„ Last Modified: April 18, 2026, 12:15 p.m.
Total resulsts: 346554
Page 1364 of 34,656
Β« previous page Β» next page
Filters