7.5

CVSS3.1

CVE-2025-70029 -

An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 1, 2026, 3:29 p.m.

8.8

CVSS3.1

CVE-2024-50619 -

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account informati…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 9:39 p.m.

7

CVSS3.1

CVE-2026-26158 - Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive …

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to pri…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:15 p.m.

8.1

CVSS3.1

CVE-2025-69871 -

A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote attackers to bypass usage li…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2026-26157 - Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitiz…

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially …

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:15 p.m.

7.5

CVSS3.1

CVE-2025-70084 -

Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileInfo function.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 3:03 p.m.

8.8

CVSS3.1

CVE-2025-65480 -

An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-70297 -

A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via an uploaded SVG file that is served as image/svg+xml and rendered by a victim s browser.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 3:33 p.m.

6.9

CVSS4.0

CVE-2026-25872 - JUNG Smart Panel 5.1 KNX Unauthenticated Path Traversal

JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesyst…

πŸ“… Published: Feb. 10, 2026, 10:25 p.m. πŸ”„ Last Modified: April 18, 2026, 12:45 p.m.

6.9

CVSS4.0

CVE-2026-25870 - DoraCMS <= 3.1 UEditor Remote Image Fetch SSRF

DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts user-supplied URLs and performs server-side HTTP or HTTPS requests without sufficient validation or destination restrictions. The implem…

πŸ“… Published: Feb. 10, 2026, 10:16 p.m. πŸ”„ Last Modified: April 15, 2026, 9:15 p.m.
Total resulsts: 347814
Page 1560 of 34,782
Β« previous page Β» next page
Filters