9.8

CVSS3.1

CVE-2026-22778 - vLLM leaks a heap address when PIL throws an error

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guessโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 9:09 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

0.0

CVE-2026-1783 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: Feb. 2, 2026, 9:03 p.m. ๐Ÿ”„ Last Modified: Feb. 16, 2026, 3:54 p.m.

7.1

CVSS3.1

CVE-2025-13096 - XML eXternal Entity injection (XXE) vulnerability affect IBM Business Automation Workflow -

IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. Aย remote atโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:56 p.m. ๐Ÿ”„ Last Modified: Feb. 12, 2026, 7:01 p.m.

4.4

CVSS3.1

CVE-2026-22780 - Rizin has a heap overflow on mach0_chained_fixups.c

Rizin is a UNIX-like reverse engineering framework and command-line toolset. Prior to 0.8.2, a heap overflow can be exploited when a malicious mach0 file, having bogus entries for the dyld chained segments, is parsed by rizin. This vulnerability is fixed in 0.8.2.

๐Ÿ“… Published: Feb. 2, 2026, 8:52 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 2:30 p.m.

6

CVSS4.0

CVE-2025-12680 - Brocade SANnav DataBase plaintext password is logged in failover logs (CVE-2025-12680)

Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after disaster recovery failover. The vulnerability could allow a remote authenticated attacker with admin privilege able to access the SANnav logs or the supportsave to read the databasโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:50 p.m. ๐Ÿ”„ Last Modified: March 3, 2026, 1:02 a.m.

5.4

CVSS3.1

CVE-2026-23476 - FacturaScripts Affected by Reflected XSS

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to 2025.8, there a reflected XSS bug in FacturaScripts. The problem is in how error messages get displayed. Twig's | raw filter is used, which skips HTML escaping. When triggering a database error (like passinโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:49 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

10

CVSS3.1

CVE-2026-23515 - RCE - Command Injection in Signal K set-system-time plugin

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated usโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:43 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

6.3

CVSS4.0

CVE-2026-24040 - jsPDF has a Shared State Race Condition in addJS Plugin

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes a shared module-scoped variable (text) to store JavaScript content. When used in a concurrent environment (e.g., a Node.js web server), this variable is shared across all requestsโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:38 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

6.9

CVSS4.0

CVE-2026-24043 - jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addMetadata function allows users to inject arbitrary XML. If given the possibility to pass unsanitized input to the addMetadata method, a user can inject arbitrary XMP metadata into the genโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:34 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.

8.7

CVSS4.0

CVE-2026-24133 - jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful BMP file that results in ouโ€ฆ

๐Ÿ“… Published: Feb. 2, 2026, 8:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 12:45 a.m.
Total resulsts: 349182
Page 1856 of 34,919
ยซ previous page ยป next page
Filters