3.1

CVSS3.1

CVE-2026-1035 - Org.keycloak.protocol.oidc: keycloak refresh token reuse bypass via toctou race condition

A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation and update of refresh token usage are not performed atomically. This โ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 8 a.m.

7.5

CVSS3.1

CVE-2025-70645 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilterCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 8:52 p.m.

5.4

CVSS3.1

CVE-2025-57681 -

The WorklogPRO - Timesheets for Jira plugin in Jira Data Center before version 4.23.6-jira10 and before version 4.23.5-jira9 allows users and attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. The vulnerability is exploited via a specially crafted payloโ€ฆ

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 2, 2026, 6:37 p.m.

7.5

CVSS3.1

CVE-2025-70651 -

Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_set function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 9:01 p.m.

7.5

CVSS3.1

CVE-2025-70644 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 8:51 p.m.

7.5

CVSS3.1

CVE-2025-70650 -

Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 8:52 p.m.

9.8

CVSS3.1

CVE-2025-69762 -

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 8:38 p.m.

7.5

CVSS3.1

CVE-2025-13878 - Malformed BRID/HHIT records can cause named to terminate unexpectedly

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-70648 -

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 9:01 p.m.

9.8

CVSS3.1

CVE-2025-69763 -

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.

๐Ÿ“… Published: Jan. 21, 2026, midnight ๐Ÿ”„ Last Modified: Jan. 26, 2026, 8:37 p.m.
Total resulsts: 347742
Page 1902 of 34,775
ยซ previous page ยป next page
Filters