Vulnerabilities (CVE)

Angry Yack Logo
Total 336347 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-25615 1 Phillipsdata 1 Blesta 2026-02-13 N/A 7.2 HIGH
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
CVE-2023-33498 1 Alistgo 1 Alist 2026-02-13 N/A 8.8 HIGH
alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.
CVE-2025-63647 1 Owntone 1 Owntone Server 2026-02-13 N/A 7.5 HIGH
A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server.
CVE-2025-24054 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-02-13 N/A 6.5 MEDIUM
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2023-4911 6 Canonical, Debian, Fedoraproject and 3 more 41 Ubuntu Linux, Debian Linux, Fedora and 38 more 2026-02-13 N/A 7.8 HIGH
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
CVE-2026-25161 1 Alistgo 1 Alist 2026-02-13 N/A 8.8 HIGH
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path traversal vulnerability in multiple file operation handlers. An authenticated attacker can bypass directory-level authorisation by injecting traversal sequences into filename components, enabling unauthorised file removal, movement and copying across user boundaries within the same storage mount. This issue has been patched in version 3.57.0.
CVE-2026-25160 1 Alistgo 1 Alist 2026-02-13 N/A 9.1 CRITICAL
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (MitM) attacks. This enables the complete decryption, theft, and manipulation of all data transmitted during storage operations, severely compromising the confidentiality and integrity of user data. This issue has been pat ...

Show More

CVE-2022-45968 1 Alistgo 1 Alist 2026-02-13 N/A 8.8 HIGH
Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).
CVE-2022-45970 1 Alistgo 1 Alist 2026-02-13 N/A 5.4 MEDIUM
Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.
CVE-2024-47067 1 Alistgo 1 Alist 2026-02-13 N/A 6.1 MEDIUM
AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.
CVE-2022-26533 1 Alistgo 1 Alist 2026-02-13 4.3 MEDIUM 6.1 MEDIUM
Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
CVE-2023-31726 1 Alistgo 1 Alist 2026-02-13 N/A 7.5 HIGH
AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.
CVE-2022-45969 1 Alistgo 1 Alist 2026-02-13 N/A 9.8 CRITICAL
Alist v3.4.0 is vulnerable to Directory Traversal,
CVE-2025-68128 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-68127 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-68126 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-68125 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-68124 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-59213 1 Microsoft 3 Configuration Manager 2403, Configuration Manager 2409, Configuration Manager 2503 2026-02-13 N/A 8.8 HIGH
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.
CVE-2025-58184 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-58182 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2025-47915 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2024-34157 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2024-34154 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2023-45291 2026-02-13 N/A N/A
Rejected reason: reserved but not needed
CVE-2023-27533 4 Fedoraproject, Haxx, Netapp and 1 more 13 Fedora, Curl, Active Iq Unified Manager and 10 more 2026-02-13 N/A 8.8 HIGH
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
CVE-2023-23915 3 Haxx, Netapp, Splunk 12 Curl, Active Iq Unified Manager, Clustered Data Ontap and 9 more 2026-02-13 N/A 6.5 MEDIUM
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlyco ...

Show More

CVE-2021-35942 3 Debian, Gnu, Netapp 7 Debian Linux, Glibc, Active Iq Unified Manager and 4 more 2026-02-13 6.4 MEDIUM 9.1 CRITICAL
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
CVE-2026-0789 1 Algosolutions 2 8180 Ip Audio Alerter, 8180 Ip Audio Alerter Firmware 2026-02-13 N/A 7.5 HIGH
ALGO 8180 IP Audio Alerter Web UI Inclusion of Authentication Cookie in Response Body Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of proper management of sensitive information. An attacker can leverage this ...

Show More

CVE-2026-0788 1 Algosolutions 2 8180 Ip Audio Alerter, 8180 Ip Audio Alerter Firmware 2026-02-13 N/A 6.1 MEDIUM
ALGO 8180 IP Audio Alerter Web UI Persistent Cross-Site Scripting Vulnerability. This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the functionality for viewing the syslog. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbi ...

Show More

CVE-2025-57155 1 Owntone 1 Owntone Server 2026-02-13 N/A 7.5 HIGH
NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after version 28.2) allows remote attackers to cause a Denial of Service.
CVE-2021-38383 1 Owntone 1 Owntone Server 2026-02-13 7.5 HIGH 9.8 CRITICAL
OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.
CVE-2025-63648 1 Owntone 1 Owntone Server 2026-02-13 N/A 7.5 HIGH
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server.
CVE-2025-57156 1 Owntone 1 Owntone Server 2026-02-13 N/A 7.5 HIGH
NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).
CVE-2025-25652 1 Eptura 1 Archibus 2026-02-13 N/A 7.5 HIGH
In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vulnerable to directory traversal.
CVE-2025-46684 1 Dell 1 Supportassist Os Recovery 2026-02-13 N/A 6.6 MEDIUM
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.
CVE-2026-0781 1 Algosolutions 2 8180 Ip Audio Alerter, 8180 Ip Audio Alerter Firmware 2026-02-13 N/A 8.8 HIGH
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulne ...

Show More

CVE-2026-0780 1 Algosolutions 2 8180 Ip Audio Alerter, 8180 Ip Audio Alerter Firmware 2026-02-13 N/A 8.8 HIGH
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulne ...

Show More

CVE-2026-0782 1 Algosolutions 2 8180 Ip Audio Alerter, 8180 Ip Audio Alerter Firmware 2026-02-13 N/A 8.8 HIGH
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP Audio Alerter devices. Authentication is required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulne ...

Show More

CVE-2025-46685 1 Dell 1 Supportassist Os Recovery 2026-02-13 N/A 7.5 HIGH
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.