7.7

CVSS3.1

CVE-2025-13523 - Cross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OAuth2 Flow

Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection…

πŸ“… Published: Feb. 6, 2026, 3:52 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 9:17 p.m.

6.9

CVSS4.0

CVE-2026-2057 - SourceCodester Medical Center Portal Management System login.php sql injection

A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

πŸ“… Published: Feb. 6, 2026, 3:32 p.m. πŸ”„ Last Modified: April 18, 2026, 1:45 p.m.

6.9

CVSS4.0

CVE-2026-2056 - D-Link DIR-605L/DIR-619L DHCP Connection Status wan_connection_status.asp information disclosure

A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Connection Status Handler. The manipulation leads to information disclosure. Remote exploitation of th…

πŸ“… Published: Feb. 6, 2026, 2:02 p.m. πŸ”„ Last Modified: April 18, 2026, 1:45 p.m.

8.3

CVSS4.0

CVE-2025-13818 - Local privilege escalation in ESET Management Agent for Windows

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

πŸ“… Published: Feb. 6, 2026, 1:13 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 4:06 p.m.

1.1

CVSS4.0

CVE-2026-1337 - Insufficient escaping of unicode characters in query log

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a precaution to treat t…

πŸ“… Published: Feb. 6, 2026, 1:13 p.m. πŸ”„ Last Modified: April 17, 2026, 10:45 p.m.

6.9

CVSS4.0

CVE-2026-2055 - D-Link DIR-605L/DIR-619L DHCP Client Information information disclosure

A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made a…

πŸ“… Published: Feb. 6, 2026, 1:02 p.m. πŸ”„ Last Modified: April 17, 2026, 10:45 p.m.

6.9

CVSS4.0

CVE-2026-2054 - D-Link DIR-605L/DIR-619L Wifi Setting information disclosure

A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been released to the public …

πŸ“… Published: Feb. 6, 2026, 12:32 p.m. πŸ”„ Last Modified: April 18, 2026, 7:45 p.m.

6.9

CVSS4.0

CVE-2026-2018 - itsourcecode School Management System controller.php sql injection

A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

πŸ“… Published: Feb. 6, 2026, 12:02 p.m. πŸ”„ Last Modified: April 18, 2026, 1:45 p.m.

9.3

CVSS4.0

CVE-2026-2017 - IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow

A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx3auth of the component POST Request Handler. The manipulation of the argument data results in stack-based buffer overflow. The attack may be performe…

πŸ“… Published: Feb. 6, 2026, 11:32 a.m. πŸ”„ Last Modified: April 17, 2026, 10:45 p.m.

6.4

CVSS3.1

CVE-2026-1293 - Yoast SEO <= 26.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'yoast-schema' Blo…

The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the `yoast-schema` block attribute in all versions up to, and including, 26.8 due to insufficient input sanitization and output escaping. This makes it poss…

πŸ“… Published: Feb. 6, 2026, 11:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:05 p.m.
Total resulsts: 349182
Page 1773 of 34,919
Β« previous page Β» next page
Filters