4.8

CVSS3.1

CVE-2026-26717 - HMAC Timing Attack Enabling Signature Forgery in OpenFUN Richie LMS

An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring resp…

πŸ“… Published: Feb. 25, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.9

CVSS4.0

CVE-2026-3134 - itsourcecode News Portal Project edit-category.php sql injection

A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. The attack may be performed from remote. The exploit has been…

πŸ“… Published: Feb. 24, 2026, 11:32 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

6.9

CVSS4.0

CVE-2026-3133 - itsourcecode Document Management System Login loging.php sql injection

A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of the component Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has …

πŸ“… Published: Feb. 24, 2026, 11:32 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

4.8

CVSS4.0

CVE-2026-26351 - GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php

GetSimpleCMS Community Edition (CE) version 3.3.16 contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored without proper output encoding. While other fields …

πŸ“… Published: Feb. 24, 2026, 10:05 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

5.5

CVSS3.1

CVE-2026-27117 - bit7z has a path traversal vulnerability

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulnerability ("Zip Slip") exists in bit7z's archive extraction functionality. The library does not adequately validate file paths contained in archive ent…

πŸ“… Published: Feb. 24, 2026, 9:46 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

9.3

CVSS3.1

CVE-2026-27593 - Statamic is vulnerable to account takeover via password reset link injection

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid a…

πŸ“… Published: Feb. 24, 2026, 9:38 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

6.9

CVSS4.0

CVE-2026-27572 - Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the set of headers. Wasmtime's implementation in the `wasmtime-wasi-http…

πŸ“… Published: Feb. 24, 2026, 9:31 p.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.9

CVSS4.0

CVE-2026-27204 - Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime did not appropriately place limits on resource allocations requested b…

πŸ“… Published: Feb. 24, 2026, 9:23 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

6.9

CVSS4.0

CVE-2026-27195 - Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling async-typed guest export functions. However, that implementation ha…

πŸ“… Published: Feb. 24, 2026, 9:15 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2026-25899 - Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpac…

πŸ“… Published: Feb. 24, 2026, 9:11 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.
Total resulsts: 346546
Page 1193 of 34,655
Β« previous page Β» next page
Filters