2.3

CVSS4.0

CVE-2026-22713 - Stored XSS through edit summaries in GrowthExperiments

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - GrowthExperiments Extension: 1.45, 1.44, 1.43, 1.39.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7:30 a.m.

7.5

CVSS3.1

CVE-2025-66744 -

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-67281 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:35 p.m.

6.5

CVSS3.1

CVE-2025-67004 -

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this …

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 7:15 p.m.

5.4

CVSS3.1

CVE-2025-67282 -

In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:32 p.m.

6.5

CVSS3.1

CVE-2025-67278 -

An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:29 p.m.

7.5

CVSS3.1

CVE-2025-67133 - Denial of Service via Unauthenticated BLE Connection

An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 20, 2026, 4 p.m.

6.5

CVSS3.1

CVE-2025-60538 -

A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:39 p.m.

6.5

CVSS3.1

CVE-2025-51626 -

SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: Jan. 22, 2026, 9:41 p.m.

8.2

CVSS3.1

CVE-2025-67070 -

A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the multi-factor authentication (MFA) mechanism during the password recovery process. This results in the ability to change the admin password and gain full access to th…

πŸ“… Published: Jan. 9, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346481
Page 1948 of 34,649
Β« previous page Β» next page
Filters