6.9

CVSS4.0

CVE-2026-2327 - markdown-it: markdown-it: Denial of Service via Regular Expression Denial of Service in linkify fun…

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers ex…

πŸ“… Published: Feb. 12, 2026, 5 a.m. πŸ”„ Last Modified: Feb. 23, 2026, 2:08 p.m.

6.3

CVSS4.0

CVE-2026-2391 - qs's arrayLimit bypass in comma parsing allows denial of service

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-…

πŸ“… Published: Feb. 12, 2026, 4:39 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:13 p.m.

7.1

CVSS4.0

CVE-2026-25676 -

The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrator privileges.

πŸ“… Published: Feb. 12, 2026, 4:26 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 3:10 p.m.

8.7

CVSS4.0

CVE-2026-26235 - JUNG Smart Visu Server 1.1.1050 - 'JUNG Smart Visu Server' Missing Authentication

JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. Attackers can send a single POST request to trigger the server reboot without requiring any authentication.

πŸ“… Published: Feb. 12, 2026, 2:31 a.m. πŸ”„ Last Modified: March 5, 2026, 1:31 a.m.

8.7

CVSS4.0

CVE-2026-26234 - JUNG Smart Visu Server - Improper Neutralization of HTTP Headers for Scripting Syntax

JUNG Smart Visu Server 1.1.1050 contains a request header manipulation vulnerability that allows unauthenticated attackers to override request URLs by injecting arbitrary values in the X-Forwarded-Host header. Attackers can manipulate proxied requests to generate tainted responses, enabling cache p…

πŸ“… Published: Feb. 12, 2026, 2:31 a.m. πŸ”„ Last Modified: March 5, 2026, 1:31 a.m.

5.3

CVSS3.1

CVE-2026-1537 - LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.6 - Missing Authorization to…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_step() function in all versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to vi…

πŸ“… Published: Feb. 12, 2026, 2:23 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

8.2

CVSS3.1

CVE-2026-23857 -

Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: Feb. 12, 2026, 2:05 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

7.8

CVSS3.1

CVE-2026-23856 -

Dell iDRAC Service Module (iSM) for Windows, versions prior to 6.0.3.1, and Dell iDRAC Service Module (iSM) for Linux, versions prior to 5.4.1.1, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to El…

πŸ“… Published: Feb. 12, 2026, 1:46 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 2:44 p.m.

8.8

CVSS3.1

CVE-2026-0969 - Arbitrary code execution in React server-side rendering of untrusted MDX content

The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.

πŸ“… Published: Feb. 12, 2026, 1:35 a.m. πŸ”„ Last Modified: Feb. 12, 2026, 3:35 p.m.

9.8

CVSS3.1

CVE-2026-1729 - AdForest <= 6.0.12 - Authentication Bypass

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthe…

πŸ“… Published: Feb. 12, 2026, 1:23 a.m. πŸ”„ Last Modified: April 8, 2026, 4:45 p.m.
Total resulsts: 344059
Page 1152 of 34,406
Β« previous page Β» next page
Filters