9.1

CVSS3.1

CVE-2026-27699 - Basic FTP has Path Traversal Vulnerability in its downloadToDir() method

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()`ย method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written ouโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 2:58 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

4.3

CVSS3.1

CVE-2026-27695 - zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service

zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share the same DynamoDB partition key (`namespace/ENTITY#{id}`). A high-traffic entity can exceed DynamoDB's per-partition throughput limits (~1,000 WCU/sec),โ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 2:56 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 8:45 p.m.

5.3

CVSS3.1

CVE-2026-2878 - Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX

In Progressยฎ Telerikยฎ UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.

๐Ÿ“… Published: Feb. 25, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2026-27692 - iccDEV has HBO in CIccTagTextDescription::Release()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags,โ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 2:40 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:30 p.m.

6.2

CVSS3.1

CVE-2026-27691 - iccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication triggers undefined behavior, potentially causing crashes or incorrect ICC profile generation when prโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 2:36 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.

5.5

CVSS3.1

CVE-2026-3203 - Buffer Over-read in Wireshark

RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

๐Ÿ“… Published: Feb. 25, 2026, 2:36 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:15 a.m.

4.7

CVSS3.1

CVE-2026-3202 - NULL Pointer Dereference in Wireshark

NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

๐Ÿ“… Published: Feb. 25, 2026, 2:35 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:15 a.m.

4.7

CVSS3.1

CVE-2026-3201 - Improperly Controlled Sequential Memory Allocation in Wireshark

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

๐Ÿ“… Published: Feb. 25, 2026, 2:35 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:15 a.m.

5.3

CVSS4.0

CVE-2026-3187 - feiyuchuixue sz-boot-parent API Endpoint upload unrestricted upload

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoint. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploitโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 2:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

5.3

CVSS4.0

CVE-2026-3186 - feiyuchuixue sz-boot-parent Password Reset password default password

A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the argument userId causes use of default passwordโ€ฆ

๐Ÿ“… Published: Feb. 25, 2026, 1:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:45 a.m.
Total resulsts: 346506
Page 1178 of 34,651
ยซ previous page ยป next page
Filters