1.2

CVSS4.0

CVE-2026-27628 - pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a workaround, one may apply the patch manually.

πŸ“… Published: Feb. 25, 2026, 2:45 a.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

10

CVSS3.1

CVE-2026-27626 - OliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extractio…

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed argument can inject she…

πŸ“… Published: Feb. 25, 2026, 2:43 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.1

CVSS3.1

CVE-2026-27612 - Repostat Vulnerable to Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard

Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability occurs because the component uses React's `dangerouslySetInnerHTML` to render the repository name (`re…

πŸ“… Published: Feb. 25, 2026, 2:38 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

6.8

CVSS4.0

CVE-2026-27621 - TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload

TypiCMS is a multilingual content management system based on the Laravel framework. A Stored Cross-Site Scripting (XSS) vulnerability exists in the file upload module of TypiCMS prior to version 16.1.7. The application allows users with file upload permissions to upload SVG files. While there is a …

πŸ“… Published: Feb. 25, 2026, 2:36 a.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

8.8

CVSS4.0

CVE-2026-27615 - ADB-Explorer: UNC Path Support in ManualAdbPath Leads to Remote Code Execution (RCE)

ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the ADB binary to be executed, to be set to a Universal Naming Convention (UNC) path in the application's settings file. This …

πŸ“… Published: Feb. 25, 2026, 2:33 a.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

9.3

CVSS3.1

CVE-2026-27614 - Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments ret…

πŸ“… Published: Feb. 25, 2026, 2:31 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

7.1

CVSS4.0

CVE-2026-27611 - FileBrowser Quantum: Password Protection Not Enforced on Shared File Links

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in …

πŸ“… Published: Feb. 25, 2026, 2:24 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

9.9

CVSS4.0

CVE-2026-27595 - Parse Dashboard has incomplete authentication on AI Agent endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, allow unauthenticated remote attackers to perform arbitrary rea…

πŸ“… Published: Feb. 25, 2026, 2:21 a.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

7

CVSS4.0

CVE-2026-27610 - Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-only master key when resolving function-typed keys. Under specific timing conditions, a read-only use…

πŸ“… Published: Feb. 25, 2026, 2:19 a.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

8.3

CVSS4.0

CVE-2026-27609 - Parse Dashboard Missing CSRF Protection on Agent Endpoint

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) lacks CSRF protection. An attacker can craft a malicious page that, when visited by an authenticated dashboard user, subm…

πŸ“… Published: Feb. 25, 2026, 2:18 a.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.
Total resulsts: 346529
Page 1188 of 34,653
Β« previous page Β» next page
Filters