6.9

CVSS4.0

CVE-2026-28351 - Manipulated RunLengthDecode streams can exhaust RAM

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode filter. This has been fixed in pypdf 6.7.4. As a workaround,…

πŸ“… Published: Feb. 27, 2026, 8:59 p.m. πŸ”„ Last Modified: April 16, 2026, 3:30 p.m.

6.8

CVSS3.1

CVE-2026-28338 - PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages

PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report formats insert rule violation messages into HTML output without escaping. When PMD analyzes untrusted source code containing crafted string literals, the generated HTML report contai…

πŸ“… Published: Feb. 27, 2026, 8:28 p.m. πŸ”„ Last Modified: April 17, 2026, 2 p.m.

5.5

CVSS4.0

CVE-2026-28288 - Dify has a user enumeration issue

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

πŸ“… Published: Feb. 27, 2026, 8:25 p.m. πŸ”„ Last Modified: April 17, 2026, 2 p.m.

8.1

CVSS3.1

CVE-2026-28272 - Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface…

πŸ“… Published: Feb. 27, 2026, 8:22 p.m. πŸ”„ Last Modified: April 18, 2026, 10:15 a.m.

6.5

CVSS3.1

CVE-2026-28271 - Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version …

πŸ“… Published: Feb. 27, 2026, 8:21 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

4.9

CVSS3.1

CVE-2026-28270 - Kiteworks Core has an Unrestricted Upload of File with Dangerous Type

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch fo…

πŸ“… Published: Feb. 27, 2026, 8:19 p.m. πŸ”„ Last Modified: April 16, 2026, 3:30 p.m.

9.8

CVSS3.1

CVE-2026-28268 - Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critica…

πŸ“… Published: Feb. 27, 2026, 8:16 p.m. πŸ”„ Last Modified: April 17, 2026, 2 p.m.

6.5

CVSS3.1

CVE-2018-25160 - HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session…

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject …

πŸ“… Published: Feb. 27, 2026, 8:15 p.m. πŸ”„ Last Modified: March 18, 2026, 7:25 p.m.

5.5

CVSS4.0

CVE-2026-28231 - pillow_heif Has Integer Overflow in Encode Path Buffer Validation that Leads to Heap Out-of-Bounds …

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds …

πŸ“… Published: Feb. 27, 2026, 8:13 p.m. πŸ”„ Last Modified: April 17, 2026, 2 p.m.

6.5

CVSS3.1

CVE-2026-3255 - HTTP::Session2 versions before 1.12 for Perl may generate weak session ids using the rand() function

HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the ep…

πŸ“… Published: Feb. 27, 2026, 8:12 p.m. πŸ”„ Last Modified: April 17, 2026, 2 p.m.
Total resulsts: 347742
Page 1256 of 34,775
Β« previous page Β» next page
Filters