5.9

CVSS3.1

CVE-2026-0990 - Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a s…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 3:55 p.m.

7.5

CVSS3.1

CVE-2025-70744 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 20, 2026, 5:35 p.m.

5.5

CVSS3.1

CVE-2025-70310 -

A heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg file.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 5:34 p.m.

8.2

CVSS3.1

CVE-2025-67823 -

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interac…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 7:38 p.m.

6.5

CVSS3.1

CVE-2025-67082 -

An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" parameters when generating a report. An authenticated attacker can exploit this issue via error-based SQL injection, allowing for the extraction of arbitrary data from the database. T…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 4:04 p.m.

6.1

CVSS3.1

CVE-2025-70890 -

A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affe…

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 4:01 p.m.

6.1

CVSS3.1

CVE-2025-67078 -

Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: March 10, 2026, 6:17 p.m.

7.5

CVSS3.1

CVE-2025-70308 -

An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 5:34 p.m.

5.5

CVSS3.1

CVE-2025-70305 -

A stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 5:35 p.m.

5.5

CVSS3.1

CVE-2025-70309 -

A stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted WAV file.

πŸ“… Published: Jan. 15, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 5:34 p.m.
Total resulsts: 342379
Page 1445 of 34,238
Β« previous page Β» next page
Filters