6.9

CVSS4.0

CVE-2026-27738 - Angular SSR has an Open Redirect via X-Forwarded-Prefix

The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the 21.x branch prior to 21.1.5 and 21.2.0-rc.1. The logic norm…

πŸ“… Published: Feb. 25, 2026, 4:40 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

2.3

CVSS4.0

CVE-2026-3193 - Chia Blockchain send_transaction cross-site request forgery

A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered dif…

πŸ“… Published: Feb. 25, 2026, 4:32 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 p.m.

6.1

CVSS3.1

CVE-2026-27736 - BigBlueButton has Open Redirect vulnerability in ApiController

BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No kno…

πŸ“… Published: Feb. 25, 2026, 4:27 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

7.4

CVSS3.1

CVE-2026-20033 - Cisco NX-OS Software Denial of Service Vulnerability

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker …

πŸ“… Published: Feb. 25, 2026, 4:26 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

7.7

CVSS3.1

CVE-2026-20048 - Cisco NX-OS Software SNMP Denial of Service Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing whe…

πŸ“… Published: Feb. 25, 2026, 4:26 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

6.7

CVSS3.1

CVE-2026-20099 - Cisco UCS Manager and FXOS Software Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root.  This …

πŸ“… Published: Feb. 25, 2026, 4:25 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

10

CVSS3.1

CVE-2026-27728 - OneUptime: OS Command Injection in Probe NetworkPathMonitor via unsanitized destination in tracerou…

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell…

πŸ“… Published: Feb. 25, 2026, 4:25 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

4.8

CVSS3.1

CVE-2026-20091 - Cisco UCS Manager and FXOS Software Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of…

πŸ“… Published: Feb. 25, 2026, 4:24 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

4.4

CVSS3.1

CVE-2026-20037 - Cisco UCS Manager File Write Vulnerability

A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system.   This vulnerability exists because unnecessary privileges are given …

πŸ“… Published: Feb. 25, 2026, 4:24 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

9.8

CVSS3.1

CVE-2026-27849 - Missing neutralization in Linksys MR9600, Linksys MX4200

Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

πŸ“… Published: Feb. 25, 2026, 4:20 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.
Total resulsts: 349182
Page 1441 of 34,919
Β« previous page Β» next page
Filters