CVE Feed

    Dashboard / CVE

    7.6
    High

    CVE-2026-1007

    Last Modified: 18 Apr 2026

    Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

    Published: 19 Jan 2026
    9.8
    Critical

    CVE-2026-0610

    Last Modified: 18 Apr 2026

    SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

    Published: 19 Jan 2026
    8.5
    High

    CVE-2026-21618

    Last Modified: 24 Jul 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.SharedAuthorizationView' modules) allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/hexpm_web/views/shared_authorization_view.ex and program routines 'Elixir.HexpmWeb.SharedAuthorizationView':render_grouped_scopes/3. This issue affects hexpm: from 617e44c71f1dd9043870205f371d375c5c4d886d before c692438684ead90c3bcbfb9ccf4e63c768c668a8; hex.pm: from 2025-10-01 before 2026-01-19.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1157

    Last Modified: 18 Apr 2026

    A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1156

    Last Modified: 18 Apr 2026

    A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1155

    Last Modified: 18 Apr 2026

    A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23909

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23910

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23911

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23912

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23913

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23914

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23915

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23916

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    Unknown

    CVE-2026-23917

    Last Modified: 20 Jan 2026

    Not used

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1154

    Last Modified: 18 Apr 2026

    A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1153

    Last Modified: 18 Apr 2026

    A vulnerability was detected in technical-laohu mpay up to 1.2.4. This affects an unknown function. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. The exploit is now public and may be used.

    Published: 19 Jan 2026
    9
    Critical

    CVE-2026-1181

    Last Modified: 18 Apr 2026

    Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could access authenticated workspace APIs in the context of a logged-in user. When chained with vulnerabilities in those external applications, this misconfiguration enables unauthorized access to workspace data, administrative actions, and bypass of IP allowlisting controls, including in GovCloud environments.

    Published: 19 Jan 2026
    2
    Low

    CVE-2026-1152

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in technical-laohu mpay up to 1.2.4. The impacted element is an unknown function of the component QR Code Image Handler. Such manipulation of the argument codeimg leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

    Published: 19 Jan 2026
    1.9
    Low

    CVE-2026-1151

    Last Modified: 18 Apr 2026

    A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1150

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. Impacted is the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument command results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

    Published: 19 Jan 2026
    8.3
    High

    CVE-2026-0603

    Last Modified: 19 Aug 2026

    A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1149

    Last Modified: 18 Apr 2026

    A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This issue affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument ip leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

    Published: 19 Jan 2026
    5.3
    Medium

    CVE-2026-1148

    Last Modified: 18 Apr 2026

    A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown code. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely.

    Published: 19 Jan 2026
    2
    Low

    CVE-2026-1147

    Last Modified: 18 Apr 2026

    A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

    Published: 19 Jan 2026
    6.5
    Medium

    CVE-2025-59355

    Last Modified: 27 Jan 2026

    A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.error(str + "decode failed", e). If the input parameter contains sensitive information such as Hive Metastore keys, plaintext passwords will be left in the log files when decoding fails, resulting in information leakage. Affected Scope Component: Sensitive fields in hive-site.xml (e.g., javax.jdo.option.ConnectionPassword) or other fields encoded in Base64. Version: Apache Linkis 1.0.0 – 1.7.0 Trigger Conditions The value of the configuration item is an invalid Base64 string. Log files are readable by users other than hive-site.xml administrators. Severity: Low The probability of Base64 decoding failure is low. The leakage is only triggered when logs at the Error level are exposed. Remediation Apache Linkis 1.8.0 and later versions have replaced the log with desensitized content. logger.error("URL decode failed: {}", e.getMessage()); // 不再输出 str Users are recommended to upgrade to version 1.8.0, which fixes the issue.

    Published: 19 Jan 2026
    7.5
    High

    CVE-2025-29847

    Last Modified: 27 Jan 2026

    A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the system's checks. This bypass can trigger a vulnerability that allows unauthorized access to system files via JDBC parameters. Scope of Impact This issue affects Apache Linkis: from 1.3.0 through 1.7.0. Severity level moderate Solution Continuously check if the connection information contains the "%" character; if it does, perform URL decoding. Users are recommended to upgrade to version 1.8.0, which fixes the issue. More questions about this vulnerability can be discussed here:  https://lists.apache.org/[email protected]:2025-9:cve

    Published: 19 Jan 2026
    2
    Low

    CVE-2026-1146

    Last Modified: 18 Apr 2026

    A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

    Published: 19 Jan 2026
    3.1
    Low

    CVE-2026-1190

    Last Modified: 18 Apr 2026

    A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of SAML responses, potentially extending the time a response is considered valid and leading to unexpected session durations or resource consumption.

    Published: 19 Jan 2026
    6.3
    Medium

    CVE-2026-1200

    Last Modified: 17 Apr 2026

    A flaw was found in the rgaufman/live555 fork of live555. A remote attacker could exploit a segmentation fault, in the `increaseBufferTo` function. This vulnerability can lead to memory corruption problems and potentially other consequences.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1145

    Last Modified: 18 Apr 2026

    A flaw has been found in quickjs-ng quickjs up to 0.11.0. Affected by this vulnerability is the function js_typed_array_constructor_ta of the file quickjs.c. This manipulation causes heap-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: 53aebe66170d545bb6265906fe4324e4477de8b4. It is suggested to install a patch to address this issue.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1144

    Last Modified: 18 Apr 2026

    A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1143

    Last Modified: 18 Apr 2026

    A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1142

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1141

    Last Modified: 18 Apr 2026

    A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1140

    Last Modified: 18 Apr 2026

    A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigExceptAli. The manipulation results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1139

    Last Modified: 18 Apr 2026

    A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1138

    Last Modified: 18 Apr 2026

    A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. Executing a manipulation can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    7.4
    High

    CVE-2026-1137

    Last Modified: 18 Apr 2026

    A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    2
    Low

    CVE-2026-1136

    Last Modified: 18 Apr 2026

    A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This manipulation of the argument content/author/title causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1135

    Last Modified: 18 Apr 2026

    A security flaw has been discovered in itsourcecode Society Management System 1.0. This impacts an unknown function of the file /admin/activity.php. The manipulation of the argument Title results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.

    Published: 19 Jan 2026
    7.5
    High

    CVE-2026-0943

    Last Modified: 18 Apr 2026

    HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

    Published: 19 Jan 2026
    2.1
    Low

    CVE-2026-1134

    Last Modified: 18 Apr 2026

    A vulnerability was identified in itsourcecode Society Management System 1.0. This affects an unknown function of the file /admin/expenses.php. The manipulation of the argument detail leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.

    Published: 19 Jan 2026
    5.5
    Medium

    CVE-2026-1133

    Last Modified: 18 Apr 2026

    A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    5.5
    Medium

    CVE-2026-1132

    Last Modified: 18 Apr 2026

    A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument folderid results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    5.5
    Medium

    CVE-2026-1131

    Last Modified: 18 Apr 2026

    A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    5.5
    Medium

    CVE-2026-1130

    Last Modified: 18 Apr 2026

    A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    5.5
    Medium

    CVE-2026-1129

    Last Modified: 18 Apr 2026

    A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 19 Jan 2026
    9.9
    Critical

    CVE-2026-22797

    Last Modified: 18 Apr 2026

    An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.

    Published: 19 Jan 2026
    5.8
    Medium

    CVE-2026-1180

    Last Modified: 15 Apr 2026

    A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using private_key_jwt. The issue allows a client to specify an arbitrary jwks_uri, which Keycloak then retrieves without validating the destination. This enables attackers to coerce the Keycloak server into making HTTP requests to internal or restricted network resources. As a result, attackers can probe internal services and cloud metadata endpoints, creating an information disclosure and reconnaissance risk.

    Published: 19 Jan 2026