Latest CVE Feed
-
3.5
LOWCVE-2025-55249
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Misconfiguration
-
2.4
LOWCVE-2025-52661
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Authentication
-
2.7
LOWCVE-2025-52660
HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Misconfiguration
-
2.8
LOWCVE-2025-52659
HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Information Disclosure
-
0.0
NACVE-2026-23838
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the ... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Misconfiguration
-
3.1
LOWCVE-2025-55252
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Authentication
-
1.8
LOWCVE-2025-55250
HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Information Disclosure
-
0.0
NACVE-2026-23878
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at least one submission on a HotCRP site could use the document API to download an... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Authorization
-
7.7
HIGHCVE-2026-23532
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clamping and the actua... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Memory Corruption
-
7.7
HIGHCVE-2026-23531
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an out-of... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Memory Corruption
-
7.7
HIGHCVE-2026-23530
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can trigger... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Memory Corruption
-
3.7
LOWCVE-2026-23522
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filter in ... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Authorization
-
8.3
HIGHCVE-2026-22850
Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped analytics export/import and permissive admin SQL import. Unauthenticated visitors can submit arbitrary pat... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Injection
-
8.4
HIGHCVE-2026-22037
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters (e.g., ... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Path Traversal
-
10.0
HIGHCVE-2026-1162
A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of the argument passwd1 causes buffer overflow. Remote exploitation of the attack is possible. The exploit ha... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2026-22031
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded characte... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2026-1161
A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the file /handler/recruitment.go. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now pu... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2026-1160
A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-68616
WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) protection bypass exists in WeasyPrint's `default_url_fetcher`. The vulnerability allows attackers to access internal network resources (s... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2025-61684
Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using Quicly... Read more
Affected Products :- Published: Jan. 19, 2026
- Modified: Jan. 19, 2026
- Vuln Type: Denial of Service