7

CVSS4.0

CVE-2026-1227 - XML External Entity Disclosure in EBO TGML Upload

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Wor…

πŸ“… Published: Feb. 11, 2026, 1:45 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

9.4

CVSS3.1

CVE-2025-8668 - Reflected XSS in E-Kalite Software Hardware Engineering's Turboard

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS.This issue affects Turboard: from 2025.07 before 2026.02.Β  NOTE:…

πŸ“… Published: Feb. 11, 2026, 1:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-2337 - Refleccted XSS on Plunet BusinessManager

A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1.

πŸ“… Published: Feb. 11, 2026, 1:28 p.m. πŸ”„ Last Modified: April 17, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2026-0910 - wpForo Forum <= 2.4.13 - Authenticated (Subscriber+) PHP Object Injection

The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13 via deserialization of untrusted input in the 'wpforo_display_array_data' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

πŸ“… Published: Feb. 11, 2026, 1:25 p.m. πŸ”„ Last Modified: April 15, 2026, 6:45 p.m.

1.7

CVSS4.0

CVE-2024-56807 - Media Streaming add-on

An out-of-bounds read vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.6 ( 202…

πŸ“… Published: Feb. 11, 2026, 12:20 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:29 p.m.

2

CVSS4.0

CVE-2024-56808 - Media Streaming add-on

A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versi…

πŸ“… Published: Feb. 11, 2026, 12:20 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:24 p.m.

0.6

CVSS4.0

CVE-2025-30266 - Qsync Central

A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4…

πŸ“… Published: Feb. 11, 2026, 12:20 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 9:38 p.m.

0.6

CVSS4.0

CVE-2025-30269 - Qsync Central

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync C…

πŸ“… Published: Feb. 11, 2026, 12:19 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 9:38 p.m.

4.9

CVSS4.0

CVE-2025-30276 - Qsync Central

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and…

πŸ“… Published: Feb. 11, 2026, 12:19 p.m. πŸ”„ Last Modified: Feb. 11, 2026, 9:38 p.m.

5.1

CVSS4.0

CVE-2025-47205 - QTS, QuTS hero

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the follo…

πŸ“… Published: Feb. 11, 2026, 12:19 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 12:59 p.m.
Total resulsts: 346102
Page 1376 of 34,611
Β« previous page Β» next page
Filters