2.3

CVSS4.0

CVE-2026-27017 - uTLS has a Chrome Parrot Fingerprint Vulnerability due to GREASE ECH Cipher Suite Mismatch

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred ci…

πŸ“… Published: Feb. 20, 2026, 2:47 a.m. πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

4.6

CVSS3.1

CVE-2026-26993 - Flare has XSS vulnerability in Raw File Preview

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and below allow users to upload files without proper content validation or sanitization. By embedding malicious JavaScript within an SVG (or other active content formats such as HTML …

πŸ“… Published: Feb. 20, 2026, 2:33 a.m. πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

6.9

CVSS4.0

CVE-2026-2821 - Fujian Smart Integrated Management Platform System XCamera.ashx sql injection

A weakness has been identified in Fujian Smart Integrated Management Platform System up to 7.5. Impacted is an unknown function of the file /Module/CRXT/Controller/XCamera.ashx. This manipulation of the argument ChannelName causes sql injection. Remote exploitation of the attack is possible. The ex…

πŸ“… Published: Feb. 20, 2026, 2:32 a.m. πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

5.1

CVSS4.0

CVE-2026-26992 - LibreNMS has Stored Cross-Site Scripting via unsanitized /port-groups name

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the port group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a port group, an HTTP POST request is sen…

πŸ“… Published: Feb. 20, 2026, 2:26 a.m. πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

6.4

CVSS3.1

CVE-2026-2384 - Quiz Maker <= 6.7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `vc_quizmaker` shortcode in all versions up to, and including, 6.7.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

πŸ“… Published: Feb. 20, 2026, 2:23 a.m. πŸ”„ Last Modified: April 15, 2026, 6:15 p.m.

5.1

CVSS4.0

CVE-2026-26991 - LibreNMS vulnerable to Stored Cross-site Scripting through unsanitized /device-groups name

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. In versions 26.1.1 and below, the device group name is not sanitized, allowing attackers with admin privileges to perform Stored Cross-Site Scripting (XSS) attacks. When a user adds a device group, an HTTP POST request is…

πŸ“… Published: Feb. 20, 2026, 2:21 a.m. πŸ”„ Last Modified: April 18, 2026, 11:45 a.m.

6.9

CVSS4.0

CVE-2026-2820 - Fujian Smart Integrated Management Platform System XAccessPermissionPlus.ashx sql injection

A security flaw has been discovered in Fujian Smart Integrated Management Platform System up to 7.5. This issue affects some unknown processing of the file /Module/CRXT/Controller/XAccessPermissionPlus.ashx. The manipulation of the argument DeviceIDS results in sql injection. The attack may be laun…

πŸ“… Published: Feb. 20, 2026, 2:02 a.m. πŸ”„ Last Modified: April 18, 2026, 11:45 a.m.

9.3

CVSS4.0

CVE-2026-26065 - calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that allow arbitrary file writes with arbitrary extension and arbitrary con…

πŸ“… Published: Feb. 20, 2026, 1:54 a.m. πŸ”„ Last Modified: April 18, 2026, 6 p.m.

9.3

CVSS4.0

CVE-2026-26064 - calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows, this leads to Remote Code Execution by writing …

πŸ“… Published: Feb. 20, 2026, 1:44 a.m. πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

5.4

CVSS3.1

CVE-2026-27016 - LibreNMS has Stored XSS in Custom OID - unit parameter missing strip_tags()

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the unit parameter in Custom OID. The Custom OID functionality lacks strip_tags() sanitization while other fields (name, oid, datatype) are sanitized. The u…

πŸ“… Published: Feb. 20, 2026, 1:34 a.m. πŸ”„ Last Modified: April 18, 2026, 11:45 a.m.
Total resulsts: 349182
Page 1536 of 34,919
Β« previous page Β» next page
Filters