7.7

CVSS3.1

CVE-2022-40620 -

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS certificates when downloading update packages through its auto-update mechanism. An attacker (suitably positioned on the network) could intercept the update request and deliver a ma…

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 2:41 p.m.

2.7

CVSS3.1

CVE-2026-1518 - Keycloak: blind server-side request forgery (ssrf) via ciba backchannel notification endpoint in ke…

A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-65888 -

A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 5:57 p.m.

6.5

CVSS3.1

CVE-2025-71001 -

A segmentation violation in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 5:17 p.m.

6.5

CVSS3.1

CVE-2025-71004 -

A segmentation violation in the oneflow.logical_or component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 4:08 p.m.

9.8

CVSS3.1

CVE-2025-61140 - jsonpath: jsonpath: Prototype Pollution vulnerability in the value function

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: Feb. 9, 2026, 7:06 p.m.

5.5

CVSS3.1

CVE-2026-23014 - perf: Ensure swevent hrtimer is properly destroyed

In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed With the change to hrtimer_try_to_cancel() in perf_swevent_cancel_hrtimer() it appears possible for the hrtimer to still be active by the time the event gets freed. Make sure th…

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 7:46 p.m.

7.5

CVSS3.1

CVE-2025-65889 -

A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 5:56 p.m.

7.5

CVSS3.1

CVE-2025-65891 -

A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative device index.

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: Feb. 3, 2026, 5:55 p.m.

7.7

CVSS3.1

CVE-2022-40619 -

FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the LAN interface of affected devices. This interface is vulnerable to unauthenticated arbitrary command injection through the funjsq_access_token parameter. This affects R6230 before …

πŸ“… Published: Jan. 28, 2026, midnight πŸ”„ Last Modified: March 9, 2026, 2:43 p.m.
Total resulsts: 344974
Page 1501 of 34,498
Β« previous page Β» next page
Filters