9.8

CVSS3.1

CVE-2025-61246 -

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 9:31 p.m.

8.4

CVSS3.1

CVE-2025-68716 -

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI or web GUI. This allows any LAN-adjacent attacker to triviall…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 4:49 p.m.

9.1

CVSS3.1

CVE-2025-56425 -

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated r…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Jan. 23, 2026, 2:15 a.m.

5.4

CVSS3.1

CVE-2025-68718 -

KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root credentials (root:12345678). The administrator cannot disable these services or change the hardcoded password. (Changing the management GUI password does not affect SSH/TELNET authenti…

πŸ“… Published: Jan. 8, 2026, midnight πŸ”„ Last Modified: Feb. 2, 2026, 4:28 p.m.

10

CVSS3.1

CVE-2026-21858 - n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resultin…

πŸ“… Published: Jan. 7, 2026, 11:57 p.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

9.8

CVSS3.1

CVE-2026-21875 - ClipBucket v5 Vulnerable to Blind SQL Injection through Channel Comments

ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add comment section within a channel. When adding a comment within a channel, there is a POST request to the /actions/ajax.php endpoint. The obj_id para…

πŸ“… Published: Jan. 7, 2026, 11:52 p.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

8.8

CVSS3.1

CVE-2026-21869 - llama.cpp has Out-of-bounds Write in llama-server

llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is parsed directly from JSON input in the llama.cpp server's completion endpoints without validation to ensure it's non-negative. When a negative value is supplied and the context fills…

πŸ“… Published: Jan. 7, 2026, 11:37 p.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

9.3

CVSS4.0

CVE-2025-15346 - wolfSSL Python library `CERT_REQUIRED` mode fails to enforce client certificate requirement

A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client certificate requirements to not be fully enforced.Β  Because the WOLFSSL_VERIFY_FAIL_IF_NO_PEER_CERT flag was not included, the behavior effectively matched CERT_OPTIONAL: a peer …

πŸ“… Published: Jan. 7, 2026, 11:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2026-21859 - Mailpit Proxy Endpoint is Vulnerable to Server-Side Request Forgery (SSRF)

Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (SSRF) vulnerability in the /proxy endpoint, allowing attackers to make requests to internal network resources. The /proxy endpoint validates http:// and https:// schemes, but it do…

πŸ“… Published: Jan. 7, 2026, 11:24 p.m. πŸ”„ Last Modified: April 18, 2026, 5 p.m.

4.3

CVSS3.1

CVE-2026-21695 - Titra API Contains Mass Assignment Vulnerability

Titra is open source project time tracking software. In versions 0.99.49 and below, an API has a Mass Assignment vulnerability which allows authenticated users to inject arbitrary fields into time entries, bypassing business logic controls via the customfields parameter. The affected endpoint uses …

πŸ“… Published: Jan. 7, 2026, 11:19 p.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.
Total resulsts: 346297
Page 1951 of 34,630
Β« previous page Β» next page
Filters