8.1

CVSS3.1

CVE-2026-26187 - lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling direct…

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath function used strings.Ha…

📅 Published: Feb. 13, 2026, 6:34 p.m. 🔄 Last Modified: Feb. 18, 2026, 9:32 p.m.

7.7

CVSS3.1

CVE-2026-25991 - Tandoor Recipes affected by Blind SSRF with Internal Network Access via Recipe Import

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The application fails to validate the destination URL afte…

📅 Published: Feb. 13, 2026, 6:29 p.m. 🔄 Last Modified: Feb. 17, 2026, 4:10 p.m.

4.9

CVSS3.1

CVE-2026-25964 - Tandoor Recipes Affected by Authenticated Local File Disclosure (LFD) via Recipe Import leads to Ar…

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import permissions to read arbitrary files on the server. This vulnerab…

📅 Published: Feb. 13, 2026, 6:27 p.m. 🔄 Last Modified: Feb. 17, 2026, 4:07 p.m.

7.8

CVSS4.0

CVE-2026-26264 - BACnet Stack WriteProperty decoding length underflow leads to OOB read and crash

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigger a length underflow in the BACnet stack, leading to an out‑of‑bounds read and a crash (DoS). The issue is in wp.c within wp_decode_service…

📅 Published: Feb. 13, 2026, 6:14 p.m. 🔄 Last Modified: Feb. 18, 2026, 6:48 p.m.

7.5

CVSS3.1

CVE-2026-21878 - BACnet Stack Improperly Limits Pathnames to a Restricted Directory

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary directori…

📅 Published: Feb. 13, 2026, 6:10 p.m. 🔄 Last Modified: Feb. 18, 2026, 6:49 p.m.

5.5

CVSS3.1

CVE-2026-21870 - The BACnet Protocol Stack library has an Off-by-one Stack-based Buffer Overflow in tokenizer_string

BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. In 1.4.2, 1.5.0.rc2, and earlier, an off-by-one stack-based buffer overflow in the ubasic interpreter causes a crash (SIGABRT) when processing string literals longe…

📅 Published: Feb. 13, 2026, 5:58 p.m. 🔄 Last Modified: Feb. 18, 2026, 6:49 p.m.

8.1

CVSS3.1

CVE-2026-26268 - Cursor sandbox escape via Git hooks

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time th…

📅 Published: Feb. 13, 2026, 4:54 p.m. 🔄 Last Modified: Feb. 18, 2026, 5:59 p.m.

5.8

CVSS4.0

CVE-2025-1790 -

Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

📅 Published: Feb. 13, 2026, 4:45 p.m. 🔄 Last Modified: Feb. 13, 2026, 9:43 p.m.

5.3

CVSS4.0

CVE-2026-26226 - beautiful-mermaid < 0.1.3 SVG Attribute Injection

beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams. User-controlled values from Mermaid style and classDef directives are interpolated into SVG attribute values without pr…

📅 Published: Feb. 13, 2026, 4:35 p.m. 🔄 Last Modified: Feb. 13, 2026, 9:43 p.m.

5.4

CVSS4.0

CVE-2026-2026 - Improper Access Control Allows Denial of Service

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.

📅 Published: Feb. 13, 2026, 4:14 p.m. 🔄 Last Modified: Feb. 24, 2026, 8:26 p.m.
Total resulsts: 343887
Page 1118 of 34,389
« previous page » next page
Filters