5.8

CVSS3.1

CVE-2026-27808 - Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API

Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{ID}/link-check) is vulnerable to Server-Side Request Forgery (SSRF). The server performs HTTP HEAD requests to every URL found in an email without validating target hosts or filter…

📅 Published: Feb. 25, 2026, 11:51 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

9.3

CVSS4.0

CVE-2026-27804 - Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google account, without knowing…

📅 Published: Feb. 25, 2026, 11:48 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

6.4

CVSS4.0

CVE-2026-27735 - mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2026.1.14, the git_add tool did not validate that file paths provided in the files argument were within the repository boundaries. Because the tool u…

📅 Published: Feb. 25, 2026, 11:45 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

5.1

CVSS4.0

CVE-2026-27711 - NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a memory corruption vulnerability in NanaZip’s UFS parser allows a crafted `.ufs/.ufs2/.img` file to trigger out-of-bounds memory access during archive open/listing. The bug is re…

📅 Published: Feb. 25, 2026, 11:44 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

5.1

CVSS4.0

CVE-2026-27710 - NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS)

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, a denial-of-service vulnerability exists in NanaZip’s `.NET Single File Application` parser. A crafted bundle can force an integer underflow in header-size calculation and trigger…

📅 Published: Feb. 25, 2026, 11:43 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

5.1

CVSS4.0

CVE-2026-27709 - NanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked RelativePat…

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to versions 6.0.1638.0 and 6.5.1638.0, NanaZip’s `.NET Single File Application` parser has an out-of-bounds read vulnerability in manifest parsing. A crafted bundle can provide a malformed `RelativePathLength` so the p…

📅 Published: Feb. 25, 2026, 11:39 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

8.8

CVSS3.1

CVE-2026-27976 - Zed Extension Sandbox Escape via Tar Symlink Following

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extension`) only performs lexical prefix checks without…

📅 Published: Feb. 25, 2026, 11:34 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

7.1

CVSS3.1

CVE-2026-27967 - Symlink Escape in Agent File Tools

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic links pointing to external paths. This bypasses the intended wor…

📅 Published: Feb. 25, 2026, 11:33 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.

7.4

CVSS3.1

CVE-2026-27800 - Zed has Zip Slip Path Traversal in Extension Archive Extraction

Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. The `extract_zip()` function in `crates/util/src/archive.rs` fails to validate ZIP entry filenames for path traversal sequences (e.g., `../`). This al…

📅 Published: Feb. 25, 2026, 11:25 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

4

CVSS3.1

CVE-2026-27799 - ImageMagick has a heap Buffer Over-read in its DJVU image format handler

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row…

📅 Published: Feb. 25, 2026, 11:20 p.m. 🔄 Last Modified: April 17, 2026, 2:45 p.m.
Total resulsts: 349182
Page 1432 of 34,919
« previous page » next page
Filters