6.5

CVSS3.1

CVE-2026-27567 - Payload has Server-Side Request Forgery (SSRF) in External File URL Uploads

Payload is a free and open source headless content management system. Prior to 3.75.0, a Server-Side Request Forgery (SSRF) vulnerability exists in Payload's external file upload functionality. When processing external URLs for file uploads, insufficient validation of HTTP redirects could allow an …

πŸ“… Published: Feb. 24, 2026, 2:22 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

6.8

CVSS3.1

CVE-2025-10010 - Integrity Validation Bypass in CryptoPro Secure Disk for BitLocker

The CPSD CryptoPro Secure Disk application boots a small Linux operating system to perform user authentication before using BitLocker to decrypt the Windows partition. The system is located on a separate unencrypted partition which can be reached by anyone with access to the hard disk. Multiple ch…

πŸ“… Published: Feb. 24, 2026, 2:13 p.m. πŸ”„ Last Modified: March 13, 2026, 7:53 p.m.

8.8

CVSS3.1

CVE-2026-27483 - MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the "Up…

πŸ“… Published: Feb. 24, 2026, 2 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

9.2

CVSS3.1

CVE-2026-27208 - api-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root Execution

bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a contain…

πŸ“… Published: Feb. 24, 2026, 1:52 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

9.8

CVSS3.1

CVE-2026-2807 - Memory safety bugs fixed in Firefox 148 and Thunderbird 148

Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.1

CVSS3.1

CVE-2026-2806 - Uninitialized memory in the Graphics: Text component

Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

5.4

CVSS3.1

CVE-2026-2804 - Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2026-2805 - Invalid pointer in the DOM: Core & HTML component

Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

7.5

CVSS3.1

CVE-2026-2803 - Information disclosure, mitigation bypass in the Settings UI component

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

4.2

CVSS3.1

CVE-2026-2802 - Race condition in the JavaScript: GC component

Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.
Total resulsts: 346298
Page 1175 of 34,630
Β« previous page Β» next page
Filters