9.8

CVSS3.1

CVE-2026-25526 - JinJava Bypass through ForTag leads to Arbitrary Java Execution

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-…

πŸ“… Published: Feb. 4, 2026, 9:26 p.m. πŸ”„ Last Modified: April 17, 2026, 11:15 p.m.

5.3

CVSS3.1

CVE-2026-25523 - Magento's X-Original-Url header can expose admin url

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.

πŸ“… Published: Feb. 4, 2026, 9:21 p.m. πŸ”„ Last Modified: April 17, 2026, 11:15 p.m.

6.5

CVSS3.1

CVE-2024-51451 - Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.

πŸ“… Published: Feb. 4, 2026, 9:21 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 8:45 p.m.

9.4

CVSS4.0

CVE-2026-25521 - Locutus is vulnerable to Prototype Pollution

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contain…

πŸ“… Published: Feb. 4, 2026, 9:20 p.m. πŸ”„ Last Modified: April 17, 2026, 11:15 p.m.

6.3

CVSS3.1

CVE-2024-43181 - Multiple Vulnerabilities in IBM Concert Software

IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: Feb. 4, 2026, 9:18 p.m. πŸ”„ Last Modified: Feb. 5, 2026, 8:44 p.m.

5.9

CVSS3.1

CVE-2026-25518 - cert-manager-controller DoS via Specially Crafted DNS Response

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. In versions from 1.18.0 to before 1.18.5 and from 1.19.0 to before 1.19.3, the cert-manager-controller performs DNS lookup…

πŸ“… Published: Feb. 4, 2026, 9:18 p.m. πŸ”„ Last Modified: April 17, 2026, 11:15 p.m.

4.3

CVSS3.1

CVE-2024-40685 - IBM Operations Analytics - Log Analysis is affected by CSRF Token Replay Attack

IBM Operations Analytics – Log Analysis versions 1.3.5.0 through 1.3.8.3 and IBM SmartCloud Analytics – Log Analysis are vulnerable to a cross-site request forgery (CSRF) vulnerability that could allow an attacker to trick a trusted user into performing unauthorized actions.

πŸ“… Published: Feb. 4, 2026, 9:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-2134 - IBM Jazz Reporting Service Denial of Service

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

πŸ“… Published: Feb. 4, 2026, 9:07 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 6:21 p.m.

3.5

CVSS3.1

CVE-2025-27550 - IBM Jazz Reporting Service Information Disclosure

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

πŸ“… Published: Feb. 4, 2026, 9:07 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 6:22 p.m.

3.5

CVSS3.1

CVE-2025-1823 - IBM Jazz Reporting Service Denial of Service

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

πŸ“… Published: Feb. 4, 2026, 9:07 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 7:41 p.m.
Total resulsts: 349182
Page 1797 of 34,919
Β« previous page Β» next page
Filters