8.1

CVSS3.1

CVE-2026-24737 - jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties…

📅 Published: Feb. 2, 2026, 8:29 p.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

8

CVSS3.1

CVE-2026-23997 - FacturaScripts has a Stored Cross-Site Scripting (XSS) in "Observations" field via History View

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity e…

📅 Published: Feb. 2, 2026, 8:19 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

7.3

CVSS4.0

CVE-2026-0924 - BuhoCleaner 1.15.2 - Local Privilege Escalation via PID reuse attack

BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoCleaner: 1.15.2.

📅 Published: Feb. 2, 2026, 8:18 p.m. 🔄 Last Modified: April 20, 2026, 2:12 p.m.

8.2

CVSS4.0

CVE-2026-1778 - TLS disabled by default in select aws/sagemaker-python-sdk configurations

Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed.

📅 Published: Feb. 2, 2026, 8:14 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

8.5

CVSS4.0

CVE-2026-1777 - Cleartext transmission of sensitive materials in aws/sagemaker-python-sdk

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training Jobs S3 output locatio…

📅 Published: Feb. 2, 2026, 8:10 p.m. 🔄 Last Modified: April 18, 2026, 2:30 p.m.

4.6

CVSS3.1

CVE-2026-24007 - Tuleap is missing CSRF protection in the Overview inconsistent items

Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This…

📅 Published: Feb. 2, 2026, 7:52 p.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

7

CVSS3.1

CVE-2026-24051 - OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search pa…

📅 Published: Feb. 2, 2026, 7:49 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

9.3

CVSS4.0

CVE-2026-24471 - Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('…

continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server to sign an arbitrary event upon user interaction. Upon a user account leaving a room (rejecting an invite), joining a room or knocking on a room, the v…

📅 Published: Feb. 2, 2026, 6:56 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.

8.6

CVSS4.0

CVE-2026-22229 - Command Injection Vulnerability on TP-Link Archer BE230 v1.2 and Deco BE25 v1.0

A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2 and Deco BE25 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resul…

📅 Published: Feb. 2, 2026, 5:58 p.m. 🔄 Last Modified: April 16, 2026, 5:45 p.m.

8.5

CVSS4.0

CVE-2026-22227 - Command Injection Vulnerability on TP-Link Archer BE230 v1.2

A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise o…

📅 Published: Feb. 2, 2026, 5:56 p.m. 🔄 Last Modified: April 18, 2026, 12:45 a.m.
Total resulsts: 349182
Page 1857 of 34,919
« previous page » next page
Filters