7.5

CVSS3.1

CVE-2025-70029 -

An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 1, 2026, 3:29 p.m.

8.8

CVSS3.1

CVE-2024-50619 -

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account informati…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 13, 2026, 9:39 p.m.

8.1

CVSS3.1

CVE-2025-69871 -

A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote attackers to bypass usage li…

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-70084 -

Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileInfo function.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 17, 2026, 3:03 p.m.

8.8

CVSS3.1

CVE-2025-65480 -

An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-70297 -

A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via an uploaded SVG file that is served as image/svg+xml and rendered by a victim s browser.

πŸ“… Published: Feb. 11, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 3:33 p.m.

6.9

CVSS4.0

CVE-2026-25872 - JUNG Smart Panel 5.1 KNX Unauthenticated Path Traversal

JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the embedded web interface. The application fails to properly validate file path input, allowing remote, unauthenticated attackers to access arbitrary files on the underlying filesyst…

πŸ“… Published: Feb. 10, 2026, 10:25 p.m. πŸ”„ Last Modified: April 18, 2026, 12:45 p.m.

6.9

CVSS4.0

CVE-2026-25870 - DoraCMS <= 3.1 UEditor Remote Image Fetch SSRF

DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts user-supplied URLs and performs server-side HTTP or HTTPS requests without sufficient validation or destination restrictions. The implem…

πŸ“… Published: Feb. 10, 2026, 10:16 p.m. πŸ”„ Last Modified: April 15, 2026, 9:15 p.m.

3.7

CVSS3.1

CVE-2026-26013 - LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side …

πŸ“… Published: Feb. 10, 2026, 9:51 p.m. πŸ”„ Last Modified: April 18, 2026, 12:45 p.m.

8.2

CVSS4.0

CVE-2026-26007 - cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do no…

πŸ“… Published: Feb. 10, 2026, 9:42 p.m. πŸ”„ Last Modified: April 18, 2026, 12:45 p.m.
Total resulsts: 349182
Page 1697 of 34,919
Β« previous page Β» next page
Filters