10

CVSS4.0

CVE-2026-26221 - Hyland OnBase Timer Services Unauthenticated .NET Remoting RCE

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and Time…

πŸ“… Published: Feb. 13, 2026, 3:21 p.m. πŸ”„ Last Modified: March 23, 2026, 3:44 p.m.

4.3

CVSS3.1

CVE-2026-25531 - Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions fo…

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowing authenticated users to duplicate tasks into pro…

πŸ“… Published: Feb. 13, 2026, 3:04 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:28 p.m.

5.1

CVSS4.0

CVE-2026-1578 - HP App – Potential Cross-Site Scripting

HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.

πŸ“… Published: Feb. 13, 2026, 2:56 p.m. πŸ”„ Last Modified: Feb. 13, 2026, 9:28 p.m.

8.3

CVSS3.1

CVE-2026-1619 - IDOR in Universal Sotware's FlexCity/Kiosk

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

πŸ“… Published: Feb. 13, 2026, 1:20 p.m. πŸ”„ Last Modified: March 2, 2026, 1:38 p.m.

8.8

CVSS3.1

CVE-2026-1618 - Admin Account Takeover in Universal Sotware's FlexCity/Kiosk

Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

πŸ“… Published: Feb. 13, 2026, 1:14 p.m. πŸ”„ Last Modified: March 2, 2026, 1:38 p.m.

8.8

CVSS3.1

CVE-2025-14349 - Business Logic Error in Universal Software's FlexCity/Kiosk

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Properly Constrained by ACLs, Privilege Escalation.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

πŸ“… Published: Feb. 13, 2026, 1:09 p.m. πŸ”„ Last Modified: March 2, 2026, 1:37 p.m.

7.3

CVSS3.1

CVE-2025-33042 - Apache Avro Java SDK: Code injection on Java generated code

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and versionΒ 1.12.0. Users are recommended to upgrade to version 1.12.1…

πŸ“… Published: Feb. 13, 2026, 11:47 a.m. πŸ”„ Last Modified: Feb. 20, 2026, 3:07 p.m.

0.0

CVE-2026-26302 -

Not used

πŸ“… Published: Feb. 13, 2026, 10:42 a.m. πŸ”„ Last Modified: Feb. 14, 2026, 3:55 a.m.

0.0

CVE-2026-26303 -

Not used

πŸ“… Published: Feb. 13, 2026, 10:42 a.m. πŸ”„ Last Modified: Feb. 14, 2026, 3:55 a.m.

0.0

CVE-2026-26297 -

Not used

πŸ“… Published: Feb. 13, 2026, 10:42 a.m. πŸ”„ Last Modified: Feb. 14, 2026, 3:55 a.m.
Total resulsts: 343887
Page 1119 of 34,389
Β« previous page Β» next page
Filters