9.3

CVSS4.0

CVE-2026-26341 - Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain admini…

📅 Published: Feb. 24, 2026, 6:40 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

8.7

CVSS4.0

CVE-2026-26340 - Tattile Smart+ / Vega / Basic <= 1.181.5 Unauthenticated RTSP Stream Disclosure

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveill…

📅 Published: Feb. 24, 2026, 6:40 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

7.6

CVSS3.1

CVE-2026-3105 - SQL Injection in Contact Activity API Sorting

SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated a…

📅 Published: Feb. 24, 2026, 6:39 p.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

10

CVSS4.0

CVE-2026-26222 - DocLink .NET Remoting Unauthenticated Arbitrary File Read/Write RCE

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling,…

📅 Published: Feb. 24, 2026, 5:33 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

6.6

CVSS3.1

CVE-2026-25603 - Path Traversal vulnerability in Linksys MR9600, Linksys MX4200

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbitrary location of the file system. This may result in the execution of shell scripts in the context o…

📅 Published: Feb. 24, 2026, 5:14 p.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

4.8

CVSS4.0

CVE-2026-27468 - Mastodon may allow unconfirmed FASP to make subscriptions

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, actions performed by a FASP to subscribe to account/content lifecycle events or to backfill content d…

📅 Published: Feb. 24, 2026, 5:12 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

6.2

CVSS4.0

CVE-2025-14963 -

A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Lo…

📅 Published: Feb. 24, 2026, 5:11 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:39 p.m.

6.1

CVSS3.1

CVE-2026-27156 - NiceGUI has XSS via Code Injection

NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_chart_method()`, and others) use an `eval()` fallback in the JavaScript-side `runMethod()` function. Whe…

📅 Published: Feb. 24, 2026, 5 p.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

5.5

CVSS4.0

CVE-2025-62512 - Piwigo Vulnerable to User Enumeration via Password Reset Endpoint

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The endpoint at password.php…

📅 Published: Feb. 24, 2026, 4:43 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:52 p.m.

2.7

CVSS4.0

CVE-2024-48928 - Piwigo's secret key can be brute forced

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making it feasible to brute-force the secret key. The CSRF token is…

📅 Published: Feb. 24, 2026, 4:39 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:52 p.m.
Total resulsts: 346556
Page 1197 of 34,656
« previous page » next page
Filters