6.9

CVSS4.0

CVE-2026-23939 - Path Traversal in Local File Store Backend

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module) allows Relative Path Traversal. This vulnerability is associated with program files lib/hexpm/store/local.ex and program routines 'Elixir.Hexpm.Storeโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:41 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, midnight

0

CVSS4.0

CVE-2026-26979 - Discourse: TL4 users are able to change status of restricted topics

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able to close, archive and pin topics in private categories they don't have access to. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are available.

๐Ÿ“… Published: Feb. 26, 2026, 7:25 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 p.m.

8.8

CVSS3.1

CVE-2026-1565 - User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registrationโ€ฆ

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:23 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 8:15 p.m.

8.7

CVSS4.0

CVE-2026-1241 - Authentication Bypass Using an Alternate Path or Channel in Pelco, Inc. Sarix Pro 3 Series IP Camerโ€ฆ

The Pelco, Inc. Sarix Professional 3 Series Cameras are vulnerable to an authentication bypass issue in their web management interface. The flaw stems from inadequate enforcement of access controls, allowing certain functionality to be accessed without proper authentication. This weakness can lead โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:21 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 p.m.

4.3

CVSS3.1

CVE-2026-26973 - Discourse doesn't scope reviewable notes to user-visible reviewables

Discourse is an open source discussion platform. Versions prior to 2025.12.2, 2026.1.1, and 2026.2.0 have an IDOR (Insecure Direct Object Reference) in `ReviewableNotesController`. When `enable_category_group_moderation` is enabled, a user belonging to a category moderation group can create or delโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 7:19 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 p.m.

6.4

CVSS4.0

CVE-2026-27510 - Unitree Go2 Mobile Program Tampering Enables Root RCE

Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLiโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 6:56 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

8.5

CVSS4.0

CVE-2026-27509 - Unitree Go2 Missing DDS Authentication Enables Adjacent RCE

Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 6:56 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

7.5

CVSS3.1

CVE-2026-27141 - Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

๐Ÿ“… Published: Feb. 26, 2026, 6:50 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 p.m.

6.1

CVSS3.1

CVE-2026-22722 - VMware Workstation for Windows null pointer dereference may allow an authenticated user to trigger โ€ฆ

A malicious actor with authenticated user privileges on a Windows based Workstation host may be able to cause a null pointer dereference error. To Remediate CVE-2026-22722, apply the patches listed in the "Fixed version" column of the 'Response Matrix'

๐Ÿ“… Published: Feb. 26, 2026, 6:35 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

5.9

CVSS3.1

CVE-2026-22715 - VMware Workstation/Fusion NAT vulnerability

VMWare Workstation and Fusion contain a logic flaw in the management of network packets.ย  Known attack vectors: A malicious actor with administrative privileges on a Guest VM may be able to interrupt or intercept network connections of other Guest VM's.ย  Resolution: To remediate CVE-2026-22715 plโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 6:29 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.
Total resulsts: 349182
Page 1421 of 34,919
ยซ previous page ยป next page
Filters