5.7

CVSS3.1

CVE-2026-24746 - InvoicePlane has a Stored Cross-Site Scripting (XSS) issue

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A Stored Cross-Site Scripting (XSS) vulnerability occurs in the Edit Quotes functions of InvoicePlane version 1.7.0. Although administrator privileges are required to exploit it, this is still consid…

📅 Published: Feb. 18, 2026, 8:51 p.m. 🔄 Last Modified: Feb. 18, 2026, 8:51 p.m.

7.1

CVSS4.0

CVE-2026-1999 - Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed unaut…

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pull request into a repository without having push access by exploiting an authorization bypass in the enable_auto_merge mutation for pull requests. This issue only affect…

📅 Published: Feb. 18, 2026, 8:44 p.m. 🔄 Last Modified: Feb. 18, 2026, 8:44 p.m.

6

CVSS4.0

CVE-2026-1355 - Missing Authorization Check in GitHub Enterprise Server Allows Unauthorized Uploads to Repository M…

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration upload endpoint. By supplying the migration identif…

📅 Published: Feb. 18, 2026, 8:42 p.m. 🔄 Last Modified: Feb. 18, 2026, 8:42 p.m.

7.6

CVSS4.0

CVE-2026-0573 - Improper Handling of HTTP Redirects vulnerability was identified in GitHub Enterprise Server that a…

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages API insecurely followed HTTP redirects when fetching artifact URLs, preserving the authorization header containing a pr…

📅 Published: Feb. 18, 2026, 8:37 p.m. 🔄 Last Modified: Feb. 18, 2026, 8:37 p.m.

6.9

CVSS4.0

CVE-2026-2668 - Rongzhitong Visual Integrated Command and Dispatch Platform User add access control

A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper access controls. The attack may be launched remotely. The e…

📅 Published: Feb. 18, 2026, 8:32 p.m. 🔄 Last Modified: Feb. 18, 2026, 8:32 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here