5.3

CVSS4.0

CVE-2026-2860 - feng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorization

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the file EmployeeController.java. The manipulation leads to improper authorization. It is possible to initiate the attack reโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 4:32 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

8.1

CVSS3.1

CVE-2026-27196 - Statamic affected by privilege escalation via stored Cross-site Scripting

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious JavaScript that execโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 4:30 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

8.1

CVSS4.0

CVE-2026-27194 - D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue hโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 4:25 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

8.2

CVSS4.0

CVE-2026-27193 - Feathers exposes internal headers via unencrypted session cookie

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the session cookie, which is signed but not encrypted, exposing internal proxy/gateway headers to clients. The OAuth serviceโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 4:09 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

7.6

CVSS4.0

CVE-2026-27192 - Feathers has an origin validation bypass via prefix matching

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comparison, allowing attackers to bypass the check by registering a domain that shares a common prefix with an allowed origโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 3:50 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

7.4

CVSS4.0

CVE-2026-27191 - Feathers: Open Redirect in OAuth callback enables account takeover

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the base origin without validation, allowing attackers to steal access tokens via URL authority injection. This leads to fuโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 3:23 a.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

6.5

CVSS3.1

CVE-2025-65995 - Apache Airflow: Disclosure of secrets to UI via kwargs

When a DAG failed during parsing, Airflowโ€™s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG.ย  The issโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 2:14 a.m. ๐Ÿ”„ Last Modified: March 8, 2026, 7:08 p.m.

6.6

CVSS3.1

CVE-2026-27189 - OpenSift: Race-prone local persistence could cause state corruption/loss

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below, use non-atomic and insufficiently synchronized local JSON persistence flows, potentially causing concurrent operations to lose updates or corrupt local state acrosโ€ฆ

๐Ÿ“… Published: Feb. 21, 2026, 12:01 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.

7.1

CVSS3.1

CVE-2026-27170 - OpenSift: SSRF risk in URL ingestion endpoint

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest allows overly permissive server-side fetch behavior and can be coerced into requesting unsafe targets. Potential access/probing of private/local netwโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 11:58 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

8.9

CVSS3.1

CVE-2026-27169 - OpenSift: Persistent XSS Chat Tool Rendering

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces using unsafe HTML interpolation patterns, leading to XSS. Stored content can execute JavaScript when laโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 11:51 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5 p.m.
Total resulsts: 349182
Page 1500 of 34,919
ยซ previous page ยป next page
Filters