8.8

CVSS3.1

CVE-2026-24512 - ingress-nginx auth-method nginx configuration injection

A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note th…

📅 Published: Feb. 3, 2026, 10:17 p.m. 🔄 Last Modified: April 16, 2026, 5:30 p.m.

8.8

CVSS3.1

CVE-2026-1580 - ingress-nginx auth-method nginx configuration injection

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to t…

📅 Published: Feb. 3, 2026, 10:16 p.m. 🔄 Last Modified: April 18, 2026, midnight

3.3

CVSS3.1

CVE-2025-33081 - Multiple Vulnerabilities in IBM Concert Software.

IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user.

📅 Published: Feb. 3, 2026, 10:14 p.m. 🔄 Last Modified: Feb. 11, 2026, 6:57 p.m.

5.4

CVSS3.1

CVE-2025-36033 - IBM Engineering Lifecycle Management - Global Configuration Management is vulnerable to cross-site …

IBM Engineering Lifecycle Management - Global Configuration Management 7.0.3 through 7.0.3 Interim Fix 017, and 7.1.0 through 7.1.0 Interim Fix 004 IBM Global Configuration Management is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScrip…

📅 Published: Feb. 3, 2026, 10:12 p.m. 🔄 Last Modified: Feb. 25, 2026, 6:55 p.m.

5.1

CVSS4.0

CVE-2020-37087 - Easy Transfer 1.7 for iOS - Persistent Cross-Site Scripting

Easy Transfer Wifi Transfer v1.7 for iOS contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts by manipulating the oldPath, newPath, and path parameters in Create Folder and Move/Edit functions. Attackers can exploit improper input validat…

📅 Published: Feb. 3, 2026, 10:09 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2020-37084 - School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the serv…

📅 Published: Feb. 3, 2026, 10:09 p.m. 🔄 Last Modified: March 5, 2026, 1:27 a.m.

5.4

CVSS3.1

CVE-2025-36094 - Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes f…

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.

📅 Published: Feb. 3, 2026, 10:06 p.m. 🔄 Last Modified: Feb. 25, 2026, 6:52 p.m.

8.7

CVSS4.0

CVE-2020-37097 - Edimax EW-7438RPn 1.13 - Information Disclosure (WiFi Password)

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configura…

📅 Published: Feb. 3, 2026, 10:01 p.m. 🔄 Last Modified: March 5, 2026, 1:27 a.m.

5.1

CVSS4.0

CVE-2020-37096 - Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)

Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.

📅 Published: Feb. 3, 2026, 10:01 p.m. 🔄 Last Modified: March 5, 2026, 1:27 a.m.

8.7

CVSS4.0

CVE-2020-37094 - EspoCRM 5.8.5 - Privilege Escalation

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and priv…

📅 Published: Feb. 3, 2026, 10:01 p.m. 🔄 Last Modified: April 7, 2026, 2:05 p.m.
Total resulsts: 346087
Page 1510 of 34,609
« previous page » next page
Filters