8.4

CVSS4.0

CVE-2026-26050 - DLL Search Path Manipulation in RICOH Journal Tool Enables Admin Code Execution

The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges.

📅 Published: Feb. 20, 2026, 8:13 a.m. 🔄 Last Modified: April 17, 2026, 5:30 p.m.

6.5

CVSS3.1

CVE-2025-59819 - Authenticated Arbitrary File Read via filepath parameter

This vulnerability allows authenticated attackers to read an arbitrary file by changing a filepath parameter into an internal system path.

📅 Published: Feb. 20, 2026, 7:58 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2026-26370 - Cross‑Site Scripting in WordPress Survey Maker Plugin

WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.

📅 Published: Feb. 20, 2026, 7:42 a.m. 🔄 Last Modified: April 17, 2026, 5:30 p.m.

5.1

CVSS4.0

CVE-2026-2825 - rachelos WeRSS we-mp-rss Article fix.py fix_html cross site scripting

A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file tools/fix.py of the component Article Module. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the …

📅 Published: Feb. 20, 2026, 6:02 a.m. 🔄 Last Modified: April 17, 2026, 5:30 p.m.

5.3

CVSS4.0

CVE-2026-2824 - Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection

A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component webmggnt. Executing a manipulation of the argument destination can lead to command injection. The attack may be performed from remote…

📅 Published: Feb. 20, 2026, 5:32 a.m. 🔄 Last Modified: April 17, 2026, 5:30 p.m.

5.3

CVSS4.0

CVE-2026-2823 - Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection

A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component webmggnt. Performing a manipulation of the argument timestr results in command injection. The attack is possible t…

📅 Published: Feb. 20, 2026, 5:02 a.m. 🔄 Last Modified: April 18, 2026, 11:45 a.m.

6.9

CVSS4.0

CVE-2026-2739 - bn.js: bn.js: Denial of Service via calling maskn(0)

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

📅 Published: Feb. 20, 2026, 5 a.m. 🔄 Last Modified: April 18, 2026, 11:45 a.m.

5.3

CVSS4.0

CVE-2026-2822 - JeecgBoot Backend airag_app,1,create_by sql injection

A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag_app,1,create_by of the component Backend Interface. Such manipulation of the argument keyword leads to sql injection. The attack can be exe…

📅 Published: Feb. 20, 2026, 4:32 a.m. 🔄 Last Modified: April 17, 2026, 5:45 p.m.

8.7

CVSS4.0

CVE-2026-26996 - minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't app…

📅 Published: Feb. 20, 2026, 3:05 a.m. 🔄 Last Modified: April 17, 2026, 5:45 p.m.

6.5

CVSS3.1

CVE-2026-26994 - uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. In versions 1.6.7 and below, uTLS did not implement the TLS 1.3 downgrade protection mechanism specified in RFC 8446 Section 4.1.3 when using a uTLS ClientHello spec.…

📅 Published: Feb. 20, 2026, 2:50 a.m. 🔄 Last Modified: April 17, 2026, 5:45 p.m.
Total resulsts: 349182
Page 1535 of 34,919
« previous page » next page
Filters