5.3

CVSS4.0

CVE-2026-2864 - feng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path traversal

A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the function pictureDelete of the file PictureController.java. Such manipulation of the argument picName leads to path traversal. The attack can be launched r…

πŸ“… Published: Feb. 21, 2026, 7:32 a.m. πŸ”„ Last Modified: April 18, 2026, 6 p.m.

6.1

CVSS3.1

CVE-2026-27469 - Isso: Stored XSS via comment website field

Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144, there is a stored Cross-Site Scripting (XSS) vulnerability affecting the website and author comment fields. The website field was HTML-escaped using quote=False, whi…

πŸ“… Published: Feb. 21, 2026, 7:24 a.m. πŸ”„ Last Modified: April 17, 2026, 5 p.m.

2

CVSS3.1

CVE-2026-27467 - BigBlueButton: Audio from participants to the server initially unmuted

BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded at the server side, so it isn't audible to any participants, but this may allow …

πŸ“… Published: Feb. 21, 2026, 7:18 a.m. πŸ”„ Last Modified: April 18, 2026, 11:30 a.m.

7.2

CVSS3.1

CVE-2026-27466 - BigBlueButton: Exposed ClamAV port enables Denial of Service

BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both p…

πŸ“… Published: Feb. 21, 2026, 7:14 a.m. πŸ”„ Last Modified: April 17, 2026, 5 p.m.

8.1

CVSS3.1

CVE-2026-27206 - Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize()

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any class specified in the @type field without restriction. When processi…

πŸ“… Published: Feb. 21, 2026, 7:01 a.m. πŸ”„ Last Modified: April 17, 2026, 5 p.m.

8.7

CVSS4.0

CVE-2026-27458 - LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description

LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authenticated user can inject a CDATA-breaking payload into a list description that escapes the XML CDATA s…

πŸ“… Published: Feb. 21, 2026, 6:54 a.m. πŸ”„ Last Modified: April 17, 2026, 5 p.m.

9.2

CVSS4.0

CVE-2026-27452 - ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.

πŸ“… Published: Feb. 21, 2026, 6:50 a.m. πŸ”„ Last Modified: April 17, 2026, 5 p.m.

9.3

CVSS4.0

CVE-2026-27471 - ERP: Document access through endpoints due to missing validation

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

πŸ“… Published: Feb. 21, 2026, 6:38 a.m. πŸ”„ Last Modified: April 18, 2026, 11:30 a.m.

5.3

CVSS4.0

CVE-2026-2863 - feng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal

A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the function deleteFile of the file FileServiceImpl.java. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has bee…

πŸ“… Published: Feb. 21, 2026, 6:02 a.m. πŸ”„ Last Modified: April 17, 2026, 5 p.m.

6.9

CVSS4.0

CVE-2026-2861 - Foswiki Changes/Viewfile/Oops information disclosure

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version…

πŸ“… Published: Feb. 21, 2026, 6:02 a.m. πŸ”„ Last Modified: April 16, 2026, 4:45 p.m.
Total resulsts: 349182
Page 1498 of 34,919
Β« previous page Β» next page
Filters