5.5

CVSS3.1

CVE-2026-23132 - drm/bridge: synopsys: dw-dp: fix error paths of dw_dp_bind

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: synopsys: dw-dp: fix error paths of dw_dp_bind Fix several issues in dw_dp_bind() error handling: 1. Missing return after drm_bridge_attach() failure - the function continued execution instead of returning an erro…

📅 Published: Feb. 14, 2026, midnight 🔄 Last Modified: March 17, 2026, 9:16 p.m.

8.1

CVSS3.1

CVE-2026-24853 - Caido has an insufficient patch for DNS rebind leading to RCE

Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP is not allowed to connect to Caido on all endpoints. But this is bypassable by injecting a X-Forwarded-Host: 127.0.0.1:8080 header. This vulnerabilit…

📅 Published: Feb. 13, 2026, 10:19 p.m. 🔄 Last Modified: Feb. 24, 2026, 8:32 p.m.

9.8

CVSS3.0

CVE-2026-26273 - Known affected by Account Takeover via Password Reset Token Leakage

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset page. This allows any unauthenticated attacker to retrieve t…

📅 Published: Feb. 13, 2026, 9:45 p.m. 🔄 Last Modified: Feb. 18, 2026, 9:01 p.m.

7.2

CVSS3.1

CVE-2026-1841 - PixelYourSite <= 11.2.0 - Unauthenticated Stored Cross-Site Scripting

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 11.2.0 due to insufficient input sanitization and output escapin…

📅 Published: Feb. 13, 2026, 9:23 p.m. 🔄 Last Modified: April 8, 2026, 6:25 p.m.

7.2

CVSS3.1

CVE-2026-1844 - PixelYourSite PRO <= 12.4.0.2 - Unauthenticated Stored Cross-Site Scripting

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 12.4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for una…

📅 Published: Feb. 13, 2026, 9:23 p.m. 🔄 Last Modified: April 8, 2026, 4:35 p.m.

8.8

CVSS3.1

CVE-2025-15157 - Starfish Review Generation & Marketing for WordPress <= 3.1.19 - Authenticated (Subscriber+) Arbitr…

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, 3.1.19. This …

📅 Published: Feb. 13, 2026, 9:23 p.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.

8.5

CVSS4.0

CVE-2026-26334 - Calero VeraSMART < 2026 R1 Hardcoded Static AES Keys Allow Decryption of Service Credentials

Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (Veramark.Core.Config class). These keys are used to encrypt the password of the service account stored in C:\\VeraSMART Data\\app.settings. An attacker with local access to the sys…

📅 Published: Feb. 13, 2026, 8:53 p.m. 🔄 Last Modified: Feb. 26, 2026, 10:45 p.m.

10

CVSS4.0

CVE-2026-26333 - Calero VeraSMART < 2022 R1 .NET Remoting Arbitrary File Read Leading to ViewState RCE

Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with TypeFilterLevel set to Full. An…

📅 Published: Feb. 13, 2026, 8:51 p.m. 🔄 Last Modified: Feb. 26, 2026, 10:46 p.m.

9.3

CVSS4.0

CVE-2026-26335 - Calero VeraSMART < 2022 R1 Static IIS Machine Keys Enable ViewState RCE

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Program Files (x86)\\Veramark\\VeraSMART\\WebRoot\\web.config. An attacker who obtains these keys can craft a valid ASP.NET ViewState payload that passe…

📅 Published: Feb. 13, 2026, 8:51 p.m. 🔄 Last Modified: Feb. 26, 2026, 10:45 p.m.

5.4

CVSS3.1

CVE-2026-26269 - Vim has a Netbeans specialKeys Stack Buffer Overflow

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (…

📅 Published: Feb. 13, 2026, 7:18 p.m. 🔄 Last Modified: Feb. 18, 2026, 9:29 p.m.
Total resulsts: 343919
Page 1120 of 34,392
« previous page » next page
Filters