9.3

CVSS3.1

CVE-2026-27593 - Statamic is vulnerable to account takeover via password reset link injection

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid a…

πŸ“… Published: Feb. 24, 2026, 9:38 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

6.9

CVSS4.0

CVE-2026-27572 - Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the set of headers. Wasmtime's implementation in the `wasmtime-wasi-http…

πŸ“… Published: Feb. 24, 2026, 9:31 p.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

6.9

CVSS4.0

CVE-2026-27204 - Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime did not appropriately place limits on resource allocations requested b…

πŸ“… Published: Feb. 24, 2026, 9:23 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

6.9

CVSS4.0

CVE-2026-27195 - Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future

Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling async-typed guest export functions. However, that implementation ha…

πŸ“… Published: Feb. 24, 2026, 9:15 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

7.5

CVSS3.1

CVE-2026-25899 - Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force an unbounded allocation on any server. A crafted 10-character cookie value triggers an attempt to allocate up to 85GB of memory via unvalidated msgpac…

πŸ“… Published: Feb. 24, 2026, 9:11 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

7.7

CVSS4.0

CVE-2026-25891 - Fiber has an Arbitrary File Read in Static Middleware on Windows

Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been pat…

πŸ“… Published: Feb. 24, 2026, 9:08 p.m. πŸ”„ Last Modified: April 18, 2026, 11 a.m.

5.5

CVSS4.0

CVE-2026-25882 - Fiber has a Denial of Service Vulnerability via Route Parameter Overflow

Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 that allows remote attackers to crash the application by sending requests to routes with more than 30 parameters. The vulnerability results from missing validation during route regi…

πŸ“… Published: Feb. 24, 2026, 9:05 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

9.3

CVSS4.0

CVE-2026-22553 - InSAT MasterSCADA BUK-TS OS Command Injection

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

πŸ“… Published: Feb. 24, 2026, 8:56 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

9.3

CVSS4.0

CVE-2026-21410 - InSAT MasterSCADA BUK-TS SQL Injection

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

πŸ“… Published: Feb. 24, 2026, 8:53 p.m. πŸ”„ Last Modified: April 17, 2026, 3:45 p.m.

6.1

CVSS3.1

CVE-2025-46320 -

A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7.

πŸ“… Published: Feb. 24, 2026, 8:30 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 4:47 p.m.
Total resulsts: 346551
Page 1194 of 34,656
Β« previous page Β» next page
Filters