6.2

CVSS4.0

CVE-2025-14963 -

A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Lo…

📅 Published: Feb. 24, 2026, 5:11 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:39 p.m.

6.1

CVSS3.1

CVE-2026-27156 - NiceGUI has XSS via Code Injection

NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_chart_method()`, and others) use an `eval()` fallback in the JavaScript-side `runMethod()` function. Whe…

📅 Published: Feb. 24, 2026, 5 p.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

5.5

CVSS4.0

CVE-2025-62512 - Piwigo Vulnerable to User Enumeration via Password Reset Endpoint

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The endpoint at password.php…

📅 Published: Feb. 24, 2026, 4:43 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:52 p.m.

2.7

CVSS4.0

CVE-2024-48928 - Piwigo's secret key can be brute forced

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making it feasible to brute-force the secret key. The CSRF token is…

📅 Published: Feb. 24, 2026, 4:39 p.m. 🔄 Last Modified: Feb. 27, 2026, 8:52 p.m.

8.9

CVSS4.0

CVE-2026-27590 - Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NAME/PATH_IN…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to slice the original path. This is unsafe for Unicode because `strings.ToLo…

📅 Published: Feb. 24, 2026, 4:33 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

6.9

CVSS4.0

CVE-2026-27589 - Caddy vulnerable to cross-origin config application via local admin API /load (caddy)

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint that replaces the entire running configuration. When origin enforcement is not enabled (`enforce_origi…

📅 Published: Feb. 24, 2026, 4:30 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

7.7

CVSS4.0

CVE-2026-27588 - Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based route/auth…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes case-sensitive due to an optimized matching path. An attacker can byp…

📅 Published: Feb. 24, 2026, 4:28 p.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.

7.7

CVSS4.0

CVE-2026-27587 - Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based route/auth…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`) it compares against the request's escaped path without lowercasing. …

📅 Published: Feb. 24, 2026, 4:26 p.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.

8.8

CVSS4.0

CVE-2026-27586 - Caddy's mTLS client authentication silently fails open when CA certificate file is missing or malfo…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or malformed. The server starts …

📅 Published: Feb. 24, 2026, 4:08 p.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.

6.9

CVSS4.0

CVE-2026-27585 - Caddy's improper sanitization of glob characters in file matcher may lead to bypassing security pro…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path related security protections. It affects users with specific Caddy and environment configurations. Ve…

📅 Published: Feb. 24, 2026, 4:06 p.m. 🔄 Last Modified: April 17, 2026, 3:45 p.m.
Total resulsts: 346560
Page 1198 of 34,656
« previous page » next page
Filters