7.5

CVSS3.1

CVE-2026-27903 - minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR seg…

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBS…

📅 Published: Feb. 26, 2026, 1:06 a.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

5.3

CVSS4.0

CVE-2026-27902 - Svelte Vulnerable to XSS via HTML Comment Injection in SSR Error Boundary Hydration Markers

Svelte performance oriented web framework. Prior to version 5.53.5, errors from `transformError` were not correctly escaped prior to being embedded in the HTML output, causing potential HTML injection and XSS if attacker-controlled content is returned from `transformError`. Version 5.53.5 fixes the…

📅 Published: Feb. 26, 2026, 12:58 a.m. 🔄 Last Modified: April 18, 2026, 7:45 p.m.

5.3

CVSS4.0

CVE-2026-27901 - Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent`

Svelte performance oriented web framework. Prior to version 5.53.5, the contents of `bind:innerText` and `bind:textContent` on `contenteditable` elements were not properly escaped. This could enable HTML injection and Cross-Site Scripting (XSS) if rendering untrusted data as the binding's initial v…

📅 Published: Feb. 26, 2026, 12:57 a.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

6.9

CVSS4.0

CVE-2026-27887 - Spin has memory leaks in various WIT interfaces

Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow connections to a database or web server which could return responses of unbounded size (e.g. tables with many rows or large content bodies), Spin may in so…

📅 Published: Feb. 26, 2026, 12:55 a.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.

5

CVSS3.1

CVE-2026-27900 - Terraform Provider Debug Logs Vulnerable to Sensitive Information Exposure

The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when debug/provider logs are explic…

📅 Published: Feb. 26, 2026, 12:53 a.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

4.9

CVSS3.1

CVE-2026-22728 - sealed-secrets /v1/rotate can widen sealing scope to cluster-wide via attacker-controlled template …

Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotation handler derives the sealing scope for the newly encrypted output from untrusted spec.template.metadata.annotations present in the input SealedSecret. By submitting a victim Sea…

📅 Published: Feb. 26, 2026, 12:50 a.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

8.8

CVSS3.1

CVE-2026-27899 - WireGuard Portal Vulnerable to Privilege Escalation to Admin via User Self-Update

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. A…

📅 Published: Feb. 26, 2026, 12:50 a.m. 🔄 Last Modified: April 18, 2026, 10:30 a.m.

7

CVSS4.0

CVE-2026-27896 - MCP Go SDK Vulnerable to Improper Handling of Case Sensitivity

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags — a field tagged json:"method" would also match "Method", "METHOD", etc. Thi…

📅 Published: Feb. 26, 2026, 12:47 a.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

8.9

CVSS4.0

CVE-2026-27830 - c3p0 vulnerable to Remote Code Execution via unsafe deserialization of userOverridesAsString proper…

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String…

📅 Published: Feb. 26, 2026, 12:45 a.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

6.6

CVSS4.0

CVE-2026-27888 - pypdf: Manipulated FlateDecode XFA streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing the `xfa` property of a reader or writer and the corresponding stream being compressed using `/FlateDecode…

📅 Published: Feb. 26, 2026, 12:42 a.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.
Total resulsts: 347263
Page 1238 of 34,727
« previous page » next page
Filters