6.9

CVSS4.0

CVE-2026-1974 - Free5GC SMF datapath.go ResolveNodeIdToIp denial of service

A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is possible. The exploit is publicly available and m…

📅 Published: Feb. 6, 2026, 2:02 a.m. 🔄 Last Modified: April 17, 2026, 11 p.m.

6.9

CVSS4.0

CVE-2026-1973 - Free5GC SMF establishPfcpSession null pointer dereference

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It …

📅 Published: Feb. 6, 2026, 1:32 a.m. 🔄 Last Modified: April 17, 2026, 11 p.m.

6.9

CVSS4.0

CVE-2026-1972 - Edimax BR-6208AC auth_check_userpass2 default credentials

A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Performing a manipulation of the argument Username/Password results in use of default credentials. The attack may be initiated remotely. The exploit has been made public and could be use…

📅 Published: Feb. 6, 2026, 1:02 a.m. 🔄 Last Modified: April 17, 2026, 11 p.m.

4.8

CVSS4.0

CVE-2026-1971 - Edimax BR-6288ACL wiz_WISP24gmanual.asp wiz_WISP24gmanual cross site scripting

A vulnerability has been found in Edimax BR-6288ACL up to 1.12. Impacted is the function wiz_WISP24gmanual of the file wiz_WISP24gmanual.asp. Such manipulation of the argument manualssid leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public…

📅 Published: Feb. 6, 2026, 12:02 a.m. 🔄 Last Modified: April 17, 2026, 11 p.m.

4.2

CVSS3.1

CVE-2026-0598 - Ansible-lightspeed: broken object level authorization leading to cross-user ai conversation context…

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the authenticated user making the request. As a result, an attacker with valid credentials could access …

📅 Published: Feb. 6, 2026, midnight 🔄 Last Modified: May 4, 2026, 9:20 p.m.

7.6

CVSS3.1

CVE-2025-70963 -

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

📅 Published: Feb. 6, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:23 p.m.

5.3

CVSS3.1

CVE-2026-23623 - Collabora Online vulnerable to Authorization Bypass

Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Development Edition version 25.04.08.2 and prior to Collabora Online versions 23.05.20.1, 24.04.17.3, and 25.04.7.5, a user with view-only rights and no download privileges can obtain …

📅 Published: Feb. 5, 2026, 11:38 p.m. 🔄 Last Modified: April 17, 2026, 11 p.m.

3.7

CVSS3.1

CVE-2025-68157 - webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that a…

📅 Published: Feb. 5, 2026, 11:08 p.m. 🔄 Last Modified: Feb. 13, 2026, 7:21 p.m.

3.7

CVSS3.1

CVE-2025-68458 - webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF be…

Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUri…

📅 Published: Feb. 5, 2026, 11:08 p.m. 🔄 Last Modified: Feb. 13, 2026, 7:16 p.m.

8.7

CVSS4.0

CVE-2025-32393 - AutoGPT has a DoS vulnerability in ReadRSSFeedBlock

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.32, there is a DoS vulnerability in ReadRSSFeedBlock. In RSSBlock, feedparser.parser is called to obtain the XML file …

📅 Published: Feb. 5, 2026, 10:57 p.m. 🔄 Last Modified: Feb. 17, 2026, 3:40 p.m.
Total resulsts: 349182
Page 1780 of 34,919
« previous page » next page
Filters