cve.li

Recent

CVE-2026-25538CWE-862

Devtron Attributes API Unauthorized Access Leading to API Token Signing Key Leakage

Published 2026-02-04 by GitHub_M

CVE-2026-1884CWE-918

ZenTao Webhook model.php fetchHook server-side request forgery

Published 2026-02-04 by VulDB

CVE-2026-25537CWE-843

jsonwebtoken has Type Confusion that leads to potential authorization bypass

Published 2026-02-04 by GitHub_M

CVE-2026-25536CWE-362

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

Published 2026-02-04 by GitHub_M

CVE-2026-25526CWE-1336

JinJava Bypass through ForTag leads to Arbitrary Java Execution

Published 2026-02-04 by GitHub_M

CVE-2026-25523CWE-200

Magento's X-Original-Url header can expose admin url

Published 2026-02-04 by GitHub_M

CVE-2024-51451CWE-644

Multiple Vulnerabilities in IBM Concert Software

Published 2026-02-04 by ibm

CVE-2026-25521CWE-1321

Locutus is vulnerable to Prototype Pollution

Published 2026-02-04 by GitHub_M

CVE-2024-43181CWE-613

Multiple Vulnerabilities in IBM Concert Software

Published 2026-02-04 by ibm

CVE-2026-25518CWE-129CWE-704

cert-manager-controller DoS via Specially Crafted DNS Response

Published 2026-02-04 by GitHub_M

Load more ↓