5

CVSS3.1

CVE-2026-1446 - XSS issue is Esri ArcGIS Pro versions 3.6.0 and earlier

There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions are required beyond standard local user access. A l…

πŸ“… Published: Jan. 26, 2026, 5:24 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 7:41 p.m.

7.8

CVSS3.1

CVE-2026-21509 - Microsoft Office Security Feature Bypass Vulnerability

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

πŸ“… Published: Jan. 26, 2026, 5:06 p.m. πŸ”„ Last Modified: April 1, 2026, 1:49 p.m.

8.5

CVSS4.0

CVE-2020-36952 - IObit Uninstaller 10 Pro - Unquoted Service Path

IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-leve…

πŸ“… Published: Jan. 26, 2026, 4 p.m. πŸ”„ Last Modified: April 7, 2026, 2:05 p.m.

7.8

CVSS3.1

CVE-2026-1284 - Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings…

An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

πŸ“… Published: Jan. 26, 2026, 1:25 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

7.8

CVSS3.1

CVE-2026-1283 - Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eD…

A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

πŸ“… Published: Jan. 26, 2026, 1:25 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 3:04 p.m.

9.9

CVSS3.1

CVE-2016-15057 - Apache Continuum: Command injection leading to RCE

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary commands o…

πŸ“… Published: Jan. 26, 2026, 11:29 a.m. πŸ”„ Last Modified: Jan. 27, 2026, 8:29 p.m.

5.1

CVSS4.0

CVE-2025-59109 - UART Leaking Sensitive Data in dormakaba registration unit 9002

The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can use the interface to exfiltrate PINs. As the devices are explicitly built as Plug-and-Play to be easily replaced, an at…

πŸ“… Published: Jan. 26, 2026, 10:06 a.m. πŸ”„ Last Modified: March 3, 2026, 6:11 p.m.

9.2

CVSS4.0

CVE-2025-59108 - Weak Default Passwords in dormakaba access manager

By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.

πŸ“… Published: Jan. 26, 2026, 10:06 a.m. πŸ”„ Last Modified: Jan. 27, 2026, 8:17 p.m.

8.5

CVSS4.0

CVE-2025-59107 - Static Firmware Encryption Password in dormakaba access manager

Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extr…

πŸ“… Published: Jan. 26, 2026, 10:06 a.m. πŸ”„ Last Modified: Jan. 27, 2026, 8:17 p.m.

8.8

CVSS3.1

CVE-2025-59106 - Web Server Running with Root Privileges in dormakaba access manager

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands w…

πŸ“… Published: Jan. 26, 2026, 10:06 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 3:54 p.m.
Total resulsts: 344676
Page 1499 of 34,468
Β« previous page Β» next page
Filters