6.9

CVSS4.0

CVE-2026-26076 - ntpd-rs affected by excessive CPU load from malformed packets

ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce moderate increases (2-4 times above normal) in cpu usage. When having NTS enabled on an ntpd-rs server, an attacker can create malformed NTS packets that take significantly more e…

πŸ“… Published: Feb. 12, 2026, 9:48 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 3:51 p.m.

6.9

CVSS4.0

CVE-2026-26075 - Cross-Site Request Forgery (CSRF) in FastGPT

FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, …

πŸ“… Published: Feb. 12, 2026, 9:42 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 4:52 p.m.

5.4

CVSS3.1

CVE-2025-14282 - Dropbear: privilege escalation via unix domain socket forwardings

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files.…

πŸ“… Published: Feb. 12, 2026, 9:37 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 9:16 p.m.

9.1

CVSS4.0

CVE-2026-26069 - Scraparr Readarr Integration exposes sensitive values as metric labels.

Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Readarr integration was enabled, the exporter exposed the configured Readarr API key as the alias metric label value. Users were affected only if all of the following conditions are…

πŸ“… Published: Feb. 12, 2026, 9:33 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 4:58 p.m.

9.3

CVSS4.0

CVE-2026-1358 - Airleader Master Unrestricted Upload of File with Dangerous Type

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

πŸ“… Published: Feb. 12, 2026, 9:24 p.m. πŸ”„ Last Modified: March 3, 2026, 9:15 p.m.

8.8

CVSS3.1

CVE-2026-26056 - Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR create/update permissions to execute arbitrary WASM code in the ATC controller context by injecting a m…

πŸ“… Published: Feb. 12, 2026, 9:11 p.m. πŸ”„ Last Modified: April 1, 2026, 8:53 p.m.

7.5

CVSS3.1

CVE-2026-26055 - Unauthenticated Admission Webhook Endpoints in Yoke ATC

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints lack proper authentication mechanisms, allowing any pod within the cluster network to directly send A…

πŸ“… Published: Feb. 12, 2026, 9:07 p.m. πŸ”„ Last Modified: April 1, 2026, 8:57 p.m.

9.4

CVSS4.0

CVE-2026-26020 - AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__)

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to 0.6.48, an authenticated user could achieve Remote Code Execution (RCE) on the backend server by embedding a disabled block inside a graph. The B…

πŸ“… Published: Feb. 12, 2026, 8:52 p.m. πŸ”„ Last Modified: Feb. 17, 2026, 8:10 p.m.

9.3

CVSS4.0

CVE-2026-26011 - Critical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Covariance --…

navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL's particle filter clustering logic. By publishing a single crafted geometry_msgs/PoseWithCovarianceStamped message with extreme covariance values to t…

πŸ“… Published: Feb. 12, 2026, 8:42 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 5 p.m.

5

CVSS3.1

CVE-2026-26005 - ClipBucket v5 enables internal network scans via an SSRF vulnerability

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #45, in Clip Bucket V5, The Remote Play allows creating video entries that reference external video URLs without uploading the video files to the server. However, by specifying an internal network host in the video URL, an SSR…

πŸ“… Published: Feb. 12, 2026, 8:34 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 2:59 p.m.
Total resulsts: 343746
Page 1113 of 34,375
Β« previous page Β» next page
Filters