9.3

CVSS4.0

CVE-2026-1474 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’, could allow an attacke…

📅 Published: Jan. 27, 2026, 4:27 p.m. 🔄 Last Modified: Feb. 10, 2026, 8:20 p.m.

9.3

CVSS4.0

CVE-2026-1473 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario’ in '/evaluacion_competencias_evalua.aspx', could allow an attacker to ex…

📅 Published: Jan. 27, 2026, 4:27 p.m. 🔄 Last Modified: Feb. 10, 2026, 8:20 p.m.

9.3

CVSS4.0

CVE-2026-1472 - Out-of-band SQL injection in Quatuor Performance Evaluation

An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'txAny' in '/evaluacion_competencias_autoeval_list.aspx', could allow an attacker to …

📅 Published: Jan. 27, 2026, 4:26 p.m. 🔄 Last Modified: Feb. 10, 2026, 8:21 p.m.

7.5

CVSS3.1

CVE-2026-22258 - Suricata DCERPC: unbounded fragment buffering leads to memory exhaustion

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB ar…

📅 Published: Jan. 27, 2026, 4:17 p.m. 🔄 Last Modified: Jan. 30, 2026, 8:09 p.m.

7.7

CVSS3.1

CVE-2026-23881 - Kyverno Denial of Service via Context Variable Amplification in Policy Engine

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially ampl…

📅 Published: Jan. 27, 2026, 4:10 p.m. 🔄 Last Modified: Feb. 2, 2026, 3:20 p.m.

10

CVSS3.1

CVE-2026-22039 - Kyverno Cross-Namespace Privilege Escalation via Policy apiCall

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller ServiceAccount, with no …

📅 Published: Jan. 27, 2026, 4:07 p.m. 🔄 Last Modified: Feb. 2, 2026, 3:13 p.m.

6.5

CVSS3.1

CVE-2026-24868 - Mitigation bypass in the Privacy: Anti-Tracking component

Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 147.0.2.

📅 Published: Jan. 27, 2026, 3:58 p.m. 🔄 Last Modified: Feb. 6, 2026, 9:16 p.m.

8.8

CVSS3.1

CVE-2026-24869 - Use-after-free in the Layout: Scrolling and Overflow component

Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.

📅 Published: Jan. 27, 2026, 3:58 p.m. 🔄 Last Modified: Feb. 26, 2026, 10:20 p.m.

7.8

CVSS3.1

CVE-2026-24875 - Integer overflow in modizer

Integer Overflow or Wraparound vulnerability in yoyofr modizer.This issue affects modizer: before 4.1.1.

📅 Published: Jan. 27, 2026, 3:55 p.m. 🔄 Last Modified: Jan. 29, 2026, 4:31 p.m.

9.1

CVSS3.1

CVE-2026-24874 - Type confusion in xray-monolith

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.

📅 Published: Jan. 27, 2026, 3:55 p.m. 🔄 Last Modified: Jan. 29, 2026, 4:31 p.m.
Total resulsts: 343947
Page 1407 of 34,395
« previous page » next page
Filters