Browse CVEs

225 CVEs analyzed. 567 pending.

All Critical High Medium Low
CVE-2025-61646 N/A

This vulnerability in MediaWiki's EnhancedChangesList.php allows attackers to potentially execute unauthorized actions or access sensitive data throug...

Feb 3, 2026
CVE-2025-61648 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's CheckUser extension. It allows attackers to inject malicious s...

Feb 3, 2026
CVE-2025-61649 N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to user information. It affects systems running CheckUser ...

Feb 3, 2026
CVE-2025-61650 N/A

This is a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's CheckUser extension that allows attackers to inject malicious scripts int...

Feb 3, 2026
CVE-2025-11173 N/A

This vulnerability in Wikimedia Foundation's OATHAuth extension allows attackers to bypass two-factor authentication (2FA) controls. It affects MediaW...

Feb 3, 2026
CVE-2025-11261 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's JavaScript language module that allows attackers to inject malicious scripts into we...

Feb 3, 2026
CVE-2025-12773 N/A

A vulnerability in Brocade SANnav's update-reports-purge-settings.sh script logs the database password to system audit logs. This allows authenticated...

Feb 3, 2026
CVE-2025-15556 N/A

This vulnerability allows attackers to intercept Notepad++ update traffic and replace legitimate updates with malicious installers. When users update ...

Feb 3, 2026
CVE-2025-61641 N/A

This vulnerability in MediaWiki's ApiQueryAllPages.php allows attackers to potentially access or manipulate page data through the API. It affects Medi...

Feb 3, 2026
CVE-2025-61642 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's HTML form components that allows attackers to inject malicious scripts in...

Feb 3, 2026
CVE-2025-61643 N/A

This vulnerability in MediaWiki's RecentChangeRCFeedNotifier.php allows attackers to execute arbitrary code or cause denial of service through imprope...

Feb 3, 2026
CVE-2025-61644 N/A

This CVE describes a cross-site scripting (XSS) vulnerability in MediaWiki's WatchlistTopSectionWidget.js component. It allows attackers to inject mal...

Feb 3, 2026
CVE-2025-61647 N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to user information through the UserInfoHandler API endpoi...

Feb 3, 2026
CVE-2025-61635 N/A

This vulnerability in Wikimedia Foundation's ConfirmEdit extension allows attackers to bypass CAPTCHA protection mechanisms. It affects all installati...

Feb 3, 2026
CVE-2025-61636 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's HTMLButtonField.php that allows attackers to inject malicious scripts into web pages...

Feb 3, 2026
CVE-2025-61637 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's edit preview functionality. Attackers can inject malicious scripts that execute in u...

Feb 3, 2026
CVE-2025-61638 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki and Parsoid that allows attackers to inject malicious scripts into web pages. It affec...

Feb 3, 2026
CVE-2025-61639 N/A

This CVE describes an information disclosure vulnerability in MediaWiki where sensitive information can be exposed to unauthorized users. The vulnerab...

Feb 3, 2026
CVE-2025-61640 N/A

This is a cross-site scripting (XSS) vulnerability in MediaWiki's RclToOrFromWidget.js component that allows attackers to inject malicious scripts int...

Feb 3, 2026
CVE-2025-61634 N/A

This vulnerability in MediaWiki's PageHTMLHandler.php allows attackers to execute unauthorized actions through the REST API. It affects all MediaWiki ...

Feb 3, 2026
CVE-2026-25228 5.0

Signal K Server versions prior to 2.20.3 on Windows systems contain a path traversal vulnerability in the applicationData API. Authenticated users can...

Feb 2, 2026
CVE-2026-25134 N/A

This vulnerability allows remote code execution in Group-Office by exploiting improper input validation in the MaintenanceController's zipLanguage act...

Feb 2, 2026
CVE-2026-25137 9.1

The NixOS Odoo package exposes the database manager without authentication, allowing unauthorized actors to delete or download the entire database and...

Feb 2, 2026
CVE-2026-25142 10.0

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...

Feb 2, 2026
CVE-2026-25144 5.3

A stored cross-site scripting (XSS) vulnerability exists in Talishar's in-game chat system where the playerID parameter in SubmitChat.php is saved wit...

Feb 2, 2026
CVE-2026-25221 N/A

PolarLearn's OAuth 2.0 implementation for GitHub and Google login is vulnerable to Login CSRF due to missing state parameter validation. This allows a...

Feb 2, 2026
CVE-2026-25222 N/A

This timing attack vulnerability in PolarLearn allows unauthenticated attackers to enumerate valid user email addresses by measuring login response ti...

Feb 2, 2026
CVE-2026-24133 N/A

This vulnerability in jsPDF allows attackers to cause denial of service by providing malicious BMP files with large width/height values in their heade...

Feb 2, 2026
CVE-2026-24471 N/A

This vulnerability in Matrix homeserver software allows a malicious remote server to trick a vulnerable server into signing arbitrary events during us...

Feb 2, 2026
CVE-2026-24737 8.1

This vulnerability in jsPDF allows attackers to inject arbitrary PDF objects, including JavaScript actions, through user-controlled input to specific ...

Feb 2, 2026
CVE-2026-24763 8.8

OpenClaw (formerly Clawdbot) versions prior to 2026.1.29 contain a command injection vulnerability in the Docker sandbox execution mechanism. Authenti...

Feb 2, 2026
CVE-2026-25059 8.8

OpenList Frontend versions before 4.1.10 contain a path traversal vulnerability in file operation handlers that allows authenticated attackers to bypa...

Feb 2, 2026
CVE-2026-25060 8.1

OpenList Frontend versions before 4.1.10 have TLS certificate verification disabled by default for storage communications, allowing Man-in-the-Middle ...

Feb 2, 2026
CVE-2026-23476 5.4

This reflected XSS vulnerability in FacturaScripts allows attackers to inject malicious scripts into error messages that get executed in users' browse...

Feb 2, 2026
CVE-2026-23515 9.9

Signal K Server versions before 1.5.0 contain a command injection vulnerability in the set-system-time plugin that allows authenticated users with wri...

Feb 2, 2026
CVE-2026-23997 8.0

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administ...

Feb 2, 2026
CVE-2026-24007 4.6

This CSRF vulnerability in Tuleap allows attackers to trick authenticated users into performing unauthorized actions, specifically creating artifact l...

Feb 2, 2026
CVE-2026-24040 N/A

CVE-2026-24040 is a concurrency vulnerability in jsPDF's addJS method that causes cross-user data leakage. When multiple users generate PDFs simultane...

Feb 2, 2026
CVE-2026-24043 N/A

This vulnerability in jsPDF allows attackers to inject arbitrary XML metadata into generated PDFs by controlling the first argument of the addMetadata...

Feb 2, 2026
CVE-2026-24051 7.0

OpenTelemetry-Go SDK versions v1.20.0 through v1.39.0 on macOS/Darwin systems are vulnerable to path hijacking attacks. An attacker with local access ...

Feb 2, 2026
CVE-2026-22778 9.8

This vulnerability in vLLM allows attackers to leak heap memory addresses by sending invalid images to the multimodal endpoint, which reduces ASLR ent...

Feb 2, 2026
CVE-2026-22780 4.4

A heap overflow vulnerability in Rizin allows attackers to execute arbitrary code or cause denial of service by tricking users into analyzing maliciou...

Feb 2, 2026
CVE-2026-1777 7.2

The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 exposes the ModelBuilder HMAC signing key in cleartext via the DescribeTrainingJob API. Thi...

Feb 2, 2026
CVE-2026-1778 5.9

This vulnerability in Amazon SageMaker Python SDK disables TLS certificate verification when importing Triton Python models, allowing HTTPS connection...

Feb 2, 2026
CVE-2026-0924 N/A

BuhoCleaner version 1.15.2 contains an insecure XPC service that allows local, unprivileged users to execute arbitrary code with root privileges. This...

Feb 2, 2026
CVE-2025-6594 4.7

This XSS vulnerability in MediaWiki's ApiSandbox.js allows attackers to inject malicious scripts into web pages viewed by other users. It affects Medi...

Feb 2, 2026
CVE-2025-6595 4.7

This CVE describes a cross-site scripting (XSS) vulnerability in Wikimedia Foundation's MultimediaViewer component. Attackers can inject malicious scr...

Feb 2, 2026
CVE-2025-6596 N/A

This is a cross-site scripting (XSS) vulnerability in Wikimedia's Vector skin that allows attackers to inject malicious scripts into web pages. It aff...

Feb 2, 2026
CVE-2025-6597 N/A

This vulnerability in MediaWiki's AuthManager.php allows attackers to bypass authentication mechanisms under specific conditions. It affects all Media...

Feb 2, 2026
CVE-2025-6927 N/A

This vulnerability in MediaWiki's block list functionality could allow attackers to access sensitive information or perform unauthorized actions. It a...

Feb 2, 2026