8.7

CVSS4.0

CVE-2026-2870 - Tenda A21 formSetQosBand set_qosMib_list stack-based overflow

A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to thโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 2:32 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 4:45 p.m.

4.8

CVSS4.0

CVE-2026-2869 - janet-lang janet handleattr specials.c janetc_varset out-of-bounds

A vulnerability was identified in janet-lang janet up to 1.40.1. Affected by this vulnerability is the function janetc_varset of the file src/core/specials.c of the component handleattr Handler. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment.โ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 2:32 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

6.9

CVSS4.0

CVE-2026-2867 - itsourcecode Vehicle Management System billaction.php sql injection

A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be uโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 1:32 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

4.8

CVSS3.1

CVE-2026-1787 - LearnPress Export Import <= 4.1.0 - Missing Authentication to Unauthenticated Migrated Course Deletโ€ฆ

The LearnPress Export Import โ€“ WordPress extension for LearnPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'delete_migrated_data' function in all versions up to, and including, 4.1.0. This makes it possible for unauthenticated attackerโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 10:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 6:15 p.m.

7.4

CVSS3.1

CVE-2026-27579 - CollabPlatform : CORS Misconfiguration Allows Arbitrary Origin With Credentials Leading to Authentiโ€ฆ

CollabPlatform is a full-stack, real-time doc collaboration platform. In all versions of CollabPlatform, the Appwrite project used by the application is misconfigured to allow arbitrary origins in CORS responses while also permitting credentialed requests. An attacker-controlled domain can issue auโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 10:22 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

4.7

CVSS3.1

CVE-2026-27492 - Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reusโ€ฆ

Lettermint Node.js SDK is the official Node.js SDK for Lettermint. In versions 1.5.0 and below, email properties (such as to, subject, html, text, and attachments) are not reset between sends when a single client instance is reused across multiple .send() calls. This can cause properties from a preโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 10:16 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

10

CVSS3.1

CVE-2026-27574 - OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-โ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 10:13 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

4.8

CVSS4.0

CVE-2026-27576 - OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with verโ€ฆ

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the ACP bridge accepts very large prompt text blocks and can assemble oversized prompt payloads before forwarding them to chat.send. Because ACP runs over local stdio, this mainly affects local ACP clients (for example IDE integrโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 10 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

6.9

CVSS4.0

CVE-2026-27488 - OpenClaw hardened cron webhook delivery against SSRF

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal endpoints without SSRF policy checks. This issue was fixed in version 2026.2.19.

๐Ÿ“… Published: Feb. 21, 2026, 9:49 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

7.6

CVSS3.1

CVE-2026-27487 - OpenClaw: Prevent shell injection in macOS keychain credential write

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, tโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 9:35 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.
Total resulsts: 349182
Page 1496 of 34,919
ยซ previous page ยป next page
Filters