8

CVSS3.1

CVE-2026-28425 - Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. That can lead to full compromise of the app…

📅 Published: Feb. 27, 2026, 10:20 p.m. 🔄 Last Modified: April 16, 2026, 6 a.m.

5.3

CVSS4.0

CVE-2026-27759 - Featured Image from Content < 1.7 Authenticated SSRF via save_post

Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticated server-side request forgery vulnerability that allows Author-level users to fetch internal HTTP resources. Attackers can exploit insecure URL fetching and file write operations …

📅 Published: Feb. 27, 2026, 10:17 p.m. 🔄 Last Modified: April 16, 2026, 3:15 p.m.

6.5

CVSS3.1

CVE-2026-28424 - Statamic's missing authorization allows access to email addresses

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 a…

📅 Published: Feb. 27, 2026, 10:14 p.m. 🔄 Last Modified: April 18, 2026, 10:15 a.m.

9.3

CVSS4.0

CVE-2026-28517 - openDCIM <= 23.04 OS Command Injection via dot Configuration Parameter

openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it directly to exec() without validation or sanitation. If an attacker can modify the f…

📅 Published: Feb. 27, 2026, 10:12 p.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

6.8

CVSS3.1

CVE-2026-28423 - Statamic Vulnerable to Server-Side Request Forgery via Glide

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP requests to arbitrary…

📅 Published: Feb. 27, 2026, 10:11 p.m. 🔄 Last Modified: April 16, 2026, 3:15 p.m.

9.3

CVSS4.0

CVE-2026-28516 - openDCIM <= 23.04 SQL Injection in Config::UpdateParameter

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitat…

📅 Published: Feb. 27, 2026, 10:11 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

9.3

CVSS4.0

CVE-2026-28515 - openDCIM <= 23.04 Missing Authorization in install.php

openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this funct…

📅 Published: Feb. 27, 2026, 10:11 p.m. 🔄 Last Modified: April 16, 2026, 3:15 p.m.

2.2

CVSS3.1

CVE-2026-28422 - Vim has stack-buffer-overflow in build_stl_str_hl()

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issue.

📅 Published: Feb. 27, 2026, 10:08 p.m. 🔄 Last Modified: April 16, 2026, 3:15 p.m.

5.3

CVSS3.1

CVE-2026-28421 - Vim has a heap-buffer-overflow and a segmentation fault

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issu…

📅 Published: Feb. 27, 2026, 10:06 p.m. 🔄 Last Modified: April 17, 2026, 2 p.m.

4.4

CVSS3.1

CVE-2026-28420 - Vim has Heap-based Buffer Overflow and OOB Read in :terminal

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.

📅 Published: Feb. 27, 2026, 10:04 p.m. 🔄 Last Modified: April 16, 2026, 3:15 p.m.
Total resulsts: 349182
Page 1397 of 34,919
« previous page » next page
Filters