7.6

CVSS4.0

CVE-2026-27970 - Angular i18n vulnerable to Cross-Site Scripting (XSS)

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 2:03 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

4.3

CVSS3.1

CVE-2026-27968 - Packistry accepts expired access tokens

Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, RepositoryAwareController::authorize() verified token presence and ability, but did not enforce token expiration. As a result, an expired deploy token with the correct ability could โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:57 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 p.m.

9.8

CVSS3.1

CVE-2026-27966 - Langflow has Remote Code Execution in CSV Agent

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChainโ€™s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Pโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:55 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.

9.3

CVSS4.0

CVE-2026-27969 - Vitess users with backup storage access can write to arbitrary file paths on restore

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest โ€” which may be files that they have also aโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:52 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:30 p.m.

8.4

CVSS4.0

CVE-2026-27965 - Vitess users with backup storage access can gain unauthorized access to production deployment envirโ€ฆ

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. Tโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:49 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

7.5

CVSS3.1

CVE-2026-27959 - Koa has Host Header Injection via `ctx.hostname`

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before the first colon without validating the input conforms to RFC 3986 hostname syntax. When a malformed Hโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:45 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

4.9

CVSS4.0

CVE-2026-27954 - LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and transferchatโ€ฆ

Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operatโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:42 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

8.8

CVSS3.1

CVE-2026-27961 - Agenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allows RCE

Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when runniโ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:39 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 10:30 a.m.

8.8

CVSS3.1

CVE-2026-27952 - Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the `numpy` package โ€ฆ

๐Ÿ“… Published: Feb. 26, 2026, 1:38 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 2:45 p.m.

5.4

CVSS3.1

CVE-2026-27948 - Copyparty vulnerable to eflected cross-site scripting via setck parameter

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

๐Ÿ“… Published: Feb. 26, 2026, 1:32 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5:45 p.m.
Total resulsts: 349182
Page 1427 of 34,919
ยซ previous page ยป next page
Filters