9.3

CVSS4.0

CVE-2026-22207 - OpenViking Missing root_api_key Allows Anonymous ROOT Access

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers …

📅 Published: Feb. 26, 2026, 8:34 p.m. 🔄 Last Modified: Feb. 26, 2026, 8:34 p.m.

8.3

CVSS4.0

CVE-2023-31364 -

Improper handling of direct memory writes in the input-output memory management unit could allow a malicious guest virtual machine (VM) to flood a host with writes, potentially causing a fatal machine check error resulting in denial of service.

📅 Published: Feb. 26, 2026, 8:33 p.m. 🔄 Last Modified: Feb. 26, 2026, 8:33 p.m.

8.7

CVSS4.0

CVE-2026-22205 - SPIP < 4.4.10 Authentication Bypass via PHP Type Juggling

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive in…

📅 Published: Feb. 26, 2026, 8:18 p.m. 🔄 Last Modified: Feb. 26, 2026, 8:18 p.m.

8.7

CVSS4.0

CVE-2026-22206 - SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code …

📅 Published: Feb. 26, 2026, 8:17 p.m. 🔄 Last Modified: Feb. 26, 2026, 8:17 p.m.

1.3

CVSS4.0

CVE-2026-27152 - DIscourse has DM communication-preference bypass when adding members

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddUsersToChannel` — a user could add targets who have blocked/ignored/muted them to an existing DM channel, bypassing per-recipien…

📅 Published: Feb. 26, 2026, 8 p.m. 🔄 Last Modified: Feb. 26, 2026, 8 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here