5.4

CVSS3.1

CVE-2025-70296 -

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 3:34 p.m.

9.8

CVSS3.1

CVE-2025-69872 - python-diskcache: python-diskcache: Arbitrary code execution via insecure pickle deserialization

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-26480 -

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 28, 2026, 4:16 a.m.

7

CVSS3.1

CVE-2026-26157 - Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitiz…

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially …

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: May 5, 2026, 8:32 p.m.

10

CVSS3.1

CVE-2025-64075 -

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-65128 -

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supplying the…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-50620 -

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user can upload executable files when inserting images in the rich text editor, and upload executable files when uploading fil…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 20, 2026, 8:18 p.m.

7.5

CVSS3.1

CVE-2024-50617 -

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieva…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 9:38 p.m.

9.8

CVSS3.1

CVE-2025-70085 -

An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_FileStateStr) into this buffer without any length checking and without using bounded format specifier…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 3:02 p.m.

9.8

CVSS3.1

CVE-2025-69874 -

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:32 a.m.
Total resulsts: 349182
Page 1696 of 34,919
Β« previous page Β» next page
Filters