6.8

CVSS3.1

CVE-2026-28338 - PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages

PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report formats insert rule violation messages into HTML output without escaping. When PMD analyzes untrusted source code containing crafted string literals, the generated HTML report contai…

📅 Published: Feb. 27, 2026, 8:28 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:28 p.m.

5.5

CVSS4.0

CVE-2026-28288 - Dify has a user enumeration issue

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

📅 Published: Feb. 27, 2026, 8:25 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:25 p.m.

8.1

CVSS3.1

CVE-2026-28272 - Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface…

📅 Published: Feb. 27, 2026, 8:22 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:22 p.m.

6.5

CVSS3.1

CVE-2026-28271 - Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version …

📅 Published: Feb. 27, 2026, 8:21 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:21 p.m.

4.9

CVSS3.1

CVE-2026-28270 - Kiteworks Core has an Unrestricted Upload of File with Dangerous Type

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch fo…

📅 Published: Feb. 27, 2026, 8:19 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:19 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here