2.3

CVSS4.0

CVE-2026-1694 - Server configuration details in HTTP headers

HTTP headers are added by the default configuration of IIS and ASP.net, and are not removed at the deployment phase of the webservices used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It unnecessarily exposes sensitive information a…

📅 Published: Feb. 26, 2026, 7:56 a.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

5.3

CVSS4.0

CVE-2026-1693 - Use of vulnerable Resource Owner Password Credentials flow

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credenti…

📅 Published: Feb. 26, 2026, 7:56 a.m. 🔄 Last Modified: April 16, 2026, 6:15 a.m.

5.3

CVSS4.0

CVE-2026-1692 - Missing origin validation in GraphicalData web service requests

A missing origin validation in WebSockets vulnerability affects the GraphicalData web services used by the WebVue, WebScheduler, TouchVue and SnapVue features of PcVue in version 12.0.0 through 16.3.3 included. It might allow a remote attacker to lure a successfully authenticated user to a maliciou…

📅 Published: Feb. 26, 2026, 7:55 a.m. 🔄 Last Modified: April 16, 2026, 4:15 p.m.

8.4

CVSS4.0

CVE-2026-25191 - FinalCode Client Installer DLL Search Path Manipulation Allows Arbitrary Code Execution

The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privilege.

📅 Published: Feb. 26, 2026, 5:39 a.m. 🔄 Last Modified: April 18, 2026, 10:30 a.m.

8.5

CVSS4.0

CVE-2026-23703 - Incorrect Default Permissions in FinalCode Client Installer Enable SYSTEM Privilege Escalation

The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.

📅 Published: Feb. 26, 2026, 5:39 a.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

8.8

CVSS3.1

CVE-2026-1311 - Worry Proof Backup <= 0.2.4 - Authenticated (Subscriber+) Path Traversal via Backup Upload

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traver…

📅 Published: Feb. 26, 2026, 4:36 a.m. 🔄 Last Modified: April 15, 2026, 6:15 p.m.

1.3

CVSS4.0

CVE-2026-27465 - Fleet: Sensitive Google Calendar credentials disclosed to low-privileged users

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorized access to Google Calendar resources associ…

📅 Published: Feb. 26, 2026, 2:54 a.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

1.2

CVSS4.0

CVE-2026-25963 - Fleet: Authorization Bypass in certificate template batch deletion for team administrators

Fleet is open source device management software. In versions prior to 4.80.1, a broken authorization check in Fleet’s certificate template deletion API could allow a team administrator to delete certificate templates belonging to other teams within the same Fleet instance. Fleet supports certificat…

📅 Published: Feb. 26, 2026, 2:49 a.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

0.6

CVSS4.0

CVE-2026-23999 - Fleet: Device lock PIN can be predicted if lock time is known

Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, the resulting PIN could potentially be derived if t…

📅 Published: Feb. 26, 2026, 2:45 a.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.

1.7

CVSS4.0

CVE-2026-24004 - Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal of individual Android devices from Fleet manageme…

📅 Published: Feb. 26, 2026, 2:43 a.m. 🔄 Last Modified: April 17, 2026, 2:30 p.m.
Total resulsts: 347374
Page 1245 of 34,738
« previous page » next page
Filters