9.8

CVSS3.1

CVE-2026-2038 - GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability

GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:13 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6 p.m.

8.8

CVSS3.0

CVE-2026-2037 - GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability

GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authenticatioโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:13 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5:15 p.m.

6.8

CVSS3.0

CVE-2026-2035 - Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability

Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. The specific flaw eโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:13 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5:15 p.m.

7.8

CVSS3.0

CVE-2026-2034 - Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability

Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must vโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:12 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

8.1

CVSS3.0

CVE-2026-2033 - MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flawโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:12 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5:15 p.m.

7.8

CVSS3.0

CVE-2026-0777 - Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability

Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a โ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:11 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5:15 p.m.

8.8

CVSS3.1

CVE-2026-0797 - GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or โ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 10:10 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5:15 p.m.

6.3

CVSS3.1

CVE-2026-27113 - Liquid Prompt arbitrary command injection via crafted Git branch names in gitstatusd backend

Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c on the master branch, arbitrary command injection can lead to code execution when a user enters a directory in a Git repositโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 9:34 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 5:15 p.m.

4.8

CVSS4.0

CVE-2026-2858 - wren-lang wren Source File wren_compiler.c peekChar out-of-bounds

A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and migโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 9:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.

6.1

CVSS3.1

CVE-2026-27120 - Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster

Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape html special characters if the extended grapheme clusters match, which allows bypassing escaping by using an extended grapheme cluster containing both the special html character andโ€ฆ

๐Ÿ“… Published: Feb. 20, 2026, 9:27 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 11:30 a.m.
Total resulsts: 349182
Page 1505 of 34,919
ยซ previous page ยป next page
Filters