7.8

CVSS3.1

CVE-2026-23083 - fou: Don't allow 0 for FOU_ATTR_IPPROTO.

In the Linux kernel, the following vulnerability has been resolved: fou: Don't allow 0 for FOU_ATTR_IPPROTO. fou_udp_recv() has the same problem mentioned in the previous patch. If FOU_ATTR_IPPROTO is set to 0, skb is not freed by fou_udp_recv() nor "resubmit"-ted in ip_protocol_deliver_rcu(). โ€ฆ

๐Ÿ“… Published: Feb. 4, 2026, midnight ๐Ÿ”„ Last Modified: April 17, 2026, 11:45 p.m.

5.5

CVSS3.1

CVE-2026-23070 - Octeontx2-af: Add proper checks for fwdata

In the Linux kernel, the following vulnerability has been resolved: Octeontx2-af: Add proper checks for fwdata firmware populates MAC address, link modes (supported, advertised) and EEPROM data in shared firmware structure which kernel access via MAC block(CGX/RPM). Accessing fwdata, on boards bโ€ฆ

๐Ÿ“… Published: Feb. 4, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 7 a.m.

5.3

CVSS4.0

CVE-2026-1813 - bolo-blog bolo-solo FreeMarker Template PicUploadProcessor.java unrestricted upload

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the argument File results in unrestricted upload. It is possible โ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 11:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:15 p.m.

10

CVSS4.0

CVE-2026-1633 - Synectix LAN 232 TRIO Missing Authentication for Critical Function

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.

๐Ÿ“… Published: Feb. 3, 2026, 11:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:15 p.m.

9.3

CVSS4.0

CVE-2026-1632 - RISS SRL MOMA Seismic Station Missing Authentication for Critical Function

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

๐Ÿ“… Published: Feb. 3, 2026, 10:59 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, midnight

5.3

CVSS4.0

CVE-2026-1812 - bolo-blog bolo-solo Filename BackupService.java importFromCnblogs path traversal

A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component Filename Handler. The manipulation of the argument File leads to path traversal. It is possible to inโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 10:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:15 p.m.

6.4

CVSS3.1

CVE-2026-1755 - Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site Scripting

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜_wp_attachment_image_altโ€™ post meta in all versions up to, and including, 0.13.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wiโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 10:22 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 1:15 a.m.

6.5

CVSS3.1

CVE-2026-24514 - ingress-nginx Admission Controller denial of service

A security issue was discovered in ingress-nginxย where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controlleโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 10:17 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, midnight

3.1

CVSS3.1

CVE-2026-24513 - ingress-nginx auth-url protection bypass

A security issue was discovered in ingress-nginxย where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errorโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 10:17 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, midnight

8.8

CVSS3.1

CVE-2026-24512 - ingress-nginx auth-method nginx configuration injection

A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note thโ€ฆ

๐Ÿ“… Published: Feb. 3, 2026, 10:17 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 5:30 p.m.
Total resulsts: 349182
Page 1818 of 34,919
ยซ previous page ยป next page
Filters