8.2

CVSS3.1

CVE-2026-26723 - Cross Site Scripting Vulnerability Allowing Remote Code Execution via Function Parameter

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

9.8

CVSS3.1

CVE-2025-70831 -

A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly sanitize user-supplied input in the mediaId parameter before using it in a system shell command. This allows an unauthenticated attacker to inject arbitrary…

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 9:30 p.m.

9.4

CVSS3.1

CVE-2026-26722 - Privilege Escalation via PIN Login in Key Systems Global Facilities Management Software

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality.

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.

9.4

CVSS3.1

CVE-2025-70833 -

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 9:30 p.m.

6.1

CVSS3.1

CVE-2025-67438 -

A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in Server before 1.9.3 allows an authenticated attacker to execute arbitrary JavaScript in a victim's browser. By uploading a crafted SVG file containing a malicious payload, an attacker can access and exfiltrate sensitive information, inclu…

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 8:29 p.m.

8.8

CVSS3.1

CVE-2026-26746 - Local File Inclusion Leading to Remote Code Execution in OpenSourcePOS 3.4.1

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code…

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 11:45 a.m.

7.1

CVSS3.1

CVE-2026-26721 - Sensitive Information Exposure via SID Query Parameter

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter.

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 11:45 a.m.

9.8

CVSS3.1

CVE-2026-26725 - Remote Privilege Escalation via AccessID in Print Shop Pro WebDesk

An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 allows a remote attacker to escalate privileges via the AccessID parameter.

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 6 p.m.

10

CVSS3.1

CVE-2021-35402 -

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).

πŸ“… Published: Feb. 20, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.7

CVSS3.1

CVE-2026-26964 - Windmill Exposes Workspace Slack OAuth Client Secrets to Non-Admin Workspace Members

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6 and below allow non-admin users to obtain Slack OAuth client secrets, which should only be accessible to workspace administrators. The GET /api/w/{workspace}/workspaces/get_s…

πŸ“… Published: Feb. 19, 2026, 11:57 p.m. πŸ”„ Last Modified: April 17, 2026, 5:45 p.m.
Total resulsts: 349182
Page 1539 of 34,919
Β« previous page Β» next page
Filters