4.3

CVSS3.1

CVE-2024-50618 -

A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the sec…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 3:01 p.m.

5.3

CVSS3.1

CVE-2024-26479 -

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 9:21 p.m.

2.9

CVSS3.1

CVE-2025-69873 - ajv: ReDoS via $data reference

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor witho…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-65127 -

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtain device …

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-67135 -

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2026-2436 - Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been free…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 21, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2025-64074 -

A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to delete arbitrary files on the host by supplying a crafted session cookie value.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2026-26158 - Busybox: busybox: arbitrary file modification and privilege escalation via unvalidated tar archive …

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to pri…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: May 5, 2026, 8:32 p.m.

7.5

CVSS3.1

CVE-2024-26477 -

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_sns, export endpoints.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 9:23 p.m.

7.8

CVSS3.1

CVE-2025-70083 -

An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirName into the local buffer DirWithSep using strcpy. The size of this buffer is OS_MAX_PATH_LEN. If the length of DirName …

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 3:03 p.m.
Total resulsts: 349182
Page 1695 of 34,919
Β« previous page Β» next page
Filters