7.7

CVSS3.1

CVE-2026-24836 - DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. V…

πŸ“… Published: Jan. 27, 2026, 11:51 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:11 p.m.

7.7

CVSS3.1

CVE-2026-24833 - DotNetNuke.Core Vulnerable to Stored XSS in Module Description

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, a module could install with richtext in its description field which could contain scripts that will run for user in the Persona Bar. Versions 9.13.10 a…

πŸ“… Published: Jan. 27, 2026, 11:49 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:12 p.m.

6.8

CVSS3.1

CVE-2026-24784 - DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a content editor could inject scripts in module headers/footers that would run for other users. Versions 9.13.10 and 10.2…

πŸ“… Published: Jan. 27, 2026, 11:47 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 8:13 p.m.

8

CVSS4.0

CVE-2026-24785 - Clatter has a PSK Validity Rule Violation issue

Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Versiosn prior to2.2.0 have a protocol compliance vulnerability. The library allowed post-quantum handshake patterns that violated the PSK validity rule (Noise Protocol Framework Sect…

πŸ“… Published: Jan. 27, 2026, 11:38 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 9:39 p.m.

6.5

CVSS3.1

CVE-2026-24134 - StudioCMS has an Authorization Bypass Through User-Controlled Key

StudioCMS is a server-side-rendered, Astro native, headless content management system. Versions prior to 0.2.0 contain a Broken Object Level Authorization (BOLA) vulnerability in the Content Management feature that allows users with the "Visitor" role to access draft content created by Editor/Admin…

πŸ“… Published: Jan. 27, 2026, 11:34 p.m. πŸ”„ Last Modified: March 17, 2026, 3:39 p.m.

10

CVSS3.1

CVE-2026-23830 - SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The library attempts to sandbox code execution by replacing the global `Function` constructor with a safe, sandboxed version (`S…

πŸ“… Published: Jan. 27, 2026, 11:32 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 8:47 p.m.

8.2

CVSS3.1

CVE-2025-55292 - In Meshtastic, an attacker can spoof licensed amateur flag for a node

Meshtastic is an open source mesh networking solution. In the current Meshtastic architecture, a Node is identified by their NodeID, generated from the MAC address, rather than their public key. This aspect downgrades the security, specifically by abusing the HAM mode which doesn't use encryption. …

πŸ“… Published: Jan. 27, 2026, 11:28 p.m. πŸ”„ Last Modified: March 2, 2026, 9:17 p.m.

8.8

CVSS3.1

CVE-2025-67645 - OpenEMR Vulnerable to Broken Access Control in Profile Edit Endpoint

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference another user’s recor…

πŸ“… Published: Jan. 27, 2026, 11:20 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 8:50 p.m.

7.1

CVSS4.0

CVE-2025-54373 - OpenEMR may expose Contents of Clinical Notes and Care Planto users who do not have Sensitivities=h…

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encounter has Sensitivit…

πŸ“… Published: Jan. 27, 2026, 11:11 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 8:58 p.m.

5.9

CVSS3.1

CVE-2026-24910 -

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).

πŸ“… Published: Jan. 27, 2026, 10:26 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345008
Page 1506 of 34,501
Β« previous page Β» next page
Filters