8.7

CVSS4.0

CVE-2026-25139 - RIOT Vulnerable to Multiple Out-of-Bounds Read When Processing Received 6LoWPAN SFR Fragments

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In version 2025.10 and prior, multiple out-of-bounds read allow any unauthenticated user, with ability to send or manipulate input packets, to …

πŸ“… Published: Feb. 4, 2026, 5:47 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

8.7

CVSS4.0

CVE-2025-69215 - OpenSTAManager has an SQL Injection in the Stampe Module

OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, there is a SQL Injection vulnerability in the Stampe Module. At time of publication, no known patch exists.

πŸ“… Published: Feb. 4, 2026, 5:42 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 3:16 p.m.

8.7

CVSS4.0

CVE-2025-69213 - OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)

OpenSTAManager is an open source management software for technical assistance and invoicing. In version 2.9.8 and prior, a SQL Injection vulnerability exists in the ajax_complete.php endpoint when handling the get_sedi operation. An authenticated attacker can inject malicious SQL code through the i…

πŸ“… Published: Feb. 4, 2026, 5:42 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 3:16 p.m.

9.4

CVSS4.0

CVE-2026-21893 - n8n Vulnerable to Command Injection in Community Package Installation

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system comma…

πŸ“… Published: Feb. 4, 2026, 5:36 p.m. πŸ”„ Last Modified: April 18, 2026, 2 p.m.

9.8

CVSS3.1

CVE-2025-64712 - Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrar…

πŸ“… Published: Feb. 4, 2026, 5:34 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 8:30 p.m.

6.5

CVSS3.1

CVE-2026-22044 - GLPI is Vulnerable to Authenticated SQL Injection

GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can perform a SQL injection. This issue has been patched in version 10.0.23.

πŸ“… Published: Feb. 4, 2026, 5:15 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

4.3

CVSS3.1

CVE-2026-23624 - GLPI is vulnerable to session stealing on externally authenticated user change

GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched…

πŸ“… Published: Feb. 4, 2026, 5:15 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

4.1

CVSS3.1

CVE-2026-22247 - GLPI is Vulnerable to SSRF via Webhooks

GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.

πŸ“… Published: Feb. 4, 2026, 5:10 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

9.4

CVSS4.0

CVE-2026-25115 - n8n is vulnerable to Python sandbox escape

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in version 2.4.8.

πŸ“… Published: Feb. 4, 2026, 4:48 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

9.4

CVSS4.0

CVE-2026-25056 - n8n Arbitrary File Write leading to RCE in n8n Merge Node

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n server's filesystem potentially leading to remote…

πŸ“… Published: Feb. 4, 2026, 4:47 p.m. πŸ”„ Last Modified: April 18, 2026, 2 p.m.
Total resulsts: 349182
Page 1802 of 34,919
Β« previous page Β» next page
Filters