6.7

CVSS3.1

CVE-2026-3091 - Uncontrolled Search Path Element Allows Local Users to Read/Write Arbitrary Files During Installati…

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in advance in the same directory as the installer.

📅 Published: Feb. 24, 2026, 2:31 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

5.9

CVSS4.0

CVE-2026-27126 - Craft CMS has Stored XSS in Table Field via "HTML" Column Type

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The application fails to sanitize the input, allowing an …

📅 Published: Feb. 24, 2026, 2:30 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

6.5

CVSS3.1

CVE-2026-26981 - OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 and 3.4.0 through 3.4.4, a heap-buffer-overflow (OOB read) occurs in the `istream_nonparallel_read` function in `ImfContex…

📅 Published: Feb. 24, 2026, 2:26 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

8.8

CVSS3.1

CVE-2026-26331 - yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a malicious…

📅 Published: Feb. 24, 2026, 2:23 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

4.9

CVSS3.1

CVE-2025-11848 -

A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-s…

📅 Published: Feb. 24, 2026, 2:14 a.m. 🔄 Last Modified: Feb. 25, 2026, 5:57 p.m.

4.9

CVSS3.1

CVE-2025-11847 -

A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-…

📅 Published: Feb. 24, 2026, 2:09 a.m. 🔄 Last Modified: Feb. 25, 2026, 6:14 p.m.

9.8

CVSS3.1

CVE-2026-26198 - ormar is vulnerable to SQL Injection through aggregate functions min() and max()

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sqlalchemy.text()` without any validation or sanitization. The `min()` and `max()` methods in the `Que…

📅 Published: Feb. 24, 2026, 2:03 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

5.3

CVSS4.0

CVE-2026-3057 - a54552239 pearProjectApi Backend Task.php dateTotalForProject sql injection

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Interface. The manipulation of the argument projectCode results in sql injection. The attack can be launc…

📅 Published: Feb. 24, 2026, 2:02 a.m. 🔄 Last Modified: April 18, 2026, 11 a.m.

5.3

CVSS4.0

CVE-2026-3054 - Alinto SOGo cross site scripting

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di…

📅 Published: Feb. 24, 2026, 2:02 a.m. 🔄 Last Modified: April 17, 2026, 4 p.m.

5.3

CVSS3.1

CVE-2026-26983 - ImageMagick: Invalid MSL <map> can result in a use after free

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` element that causes it to use an image after it has been freed. Versions 7.1.2-15 and 6.9.13-40 cont…

📅 Published: Feb. 24, 2026, 2:01 a.m. 🔄 Last Modified: April 16, 2026, 4:30 p.m.
Total resulsts: 349182
Page 1472 of 34,919
« previous page » next page
Filters