8.7

CVSS4.0

CVE-2026-26234 - JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache p…

πŸ“… Published: Feb. 12, 2026, 2:31 a.m. πŸ”„ Last Modified: March 5, 2026, 1:31 a.m.

5.3

CVSS3.1

CVE-2026-1537 - LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_step() function in all versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to vi…

πŸ“… Published: Feb. 12, 2026, 2:23 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

8.2

CVSS3.1

CVE-2026-23857 -

Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: Feb. 12, 2026, 2:05 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

7.8

CVSS3.1

CVE-2026-23856 -

Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to El…

πŸ“… Published: Feb. 12, 2026, 1:46 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

8.8

CVSS3.1

CVE-2026-0969 - Arbitrary code execution in React server-side rendering of untrusted MDX content

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.

πŸ“… Published: Feb. 12, 2026, 1:35 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 3:35 p.m.

9.8

CVSS3.1

CVE-2026-1729 - AdForest <= 6.0.12 - Authentication Bypass

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthe…

πŸ“… Published: Feb. 12, 2026, 1:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:45 p.m.

7.7

CVSS3.1

CVE-2025-61879 -

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 19, 2026, 3:55 p.m.

5.4

CVSS3.1

CVE-2026-25828 -

grub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitize the $root parameter to resolve_device(). NOTE: a third party reports "exploitation may not be feasible under normal conditions and may depend on specific imp…

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: March 4, 2026, 8:16 a.m.

7.5

CVSS3.1

CVE-2025-69806 -

p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get relative information leakage via a packet sent to the server

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 5:21 p.m.

8.8

CVSS3.1

CVE-2025-61880 -

In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.

πŸ“… Published: Feb. 12, 2026, midnight πŸ”„ Last Modified: Feb. 19, 2026, 3:55 p.m.
Total resulsts: 343975
Page 1144 of 34,398
Β« previous page Β» next page
Filters