4.8

CVSS4.0

CVE-2026-2817 - Spring Data Geode Insecure Temporary Directory Usage

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local user with basic privileges can access another user’s extracted snapshot contents, leading to unintended exposure of cach…

📅 Published: Feb. 19, 2026, 5:18 p.m. 🔄 Last Modified: April 17, 2026, 6:15 p.m.

9.3

CVSS4.0

CVE-2026-26339 - Hyland Alfresco Transformation Service Argument Injection RCE

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability, which exists in the document processing functionality.

📅 Published: Feb. 19, 2026, 5:04 p.m. 🔄 Last Modified: April 17, 2026, 6:15 p.m.

6.9

CVSS4.0

CVE-2026-26338 - Hyland Alfresco Transformation Service SSRF

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing functionality.

📅 Published: Feb. 19, 2026, 5:03 p.m. 🔄 Last Modified: April 16, 2026, 5 p.m.

8.8

CVSS4.0

CVE-2026-26337 - Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.

📅 Published: Feb. 19, 2026, 5:01 p.m. 🔄 Last Modified: April 17, 2026, 6:15 p.m.

7.5

CVSS3.1

CVE-2026-2232 - Product Table and List Builder for WooCommerce Lite <= 4.6.2 - Unauthenticated Time-Based SQL Injec…

The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin…

📅 Published: Feb. 19, 2026, 4:24 p.m. 🔄 Last Modified: April 15, 2026, 5:15 p.m.

7.5

CVSS3.1

CVE-2026-1581 - wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…

📅 Published: Feb. 19, 2026, 4:24 p.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

10

CVSS3.1

CVE-2026-26030 - Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execut…

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As …

📅 Published: Feb. 19, 2026, 4 p.m. 🔄 Last Modified: April 17, 2026, 6:15 p.m.

9.4

CVSS3.1

CVE-2026-24834 - Kata Container to Guest micro VM privilege escalation

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM…

📅 Published: Feb. 19, 2026, 3:57 p.m. 🔄 Last Modified: April 18, 2026, noon

8.7

CVSS4.0

CVE-2026-26336 - Hyland Alfresco Improper Authorization Arbitrary File Read

Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.

📅 Published: Feb. 19, 2026, 3:56 p.m. 🔄 Last Modified: April 16, 2026, 6:30 a.m.

9.2

CVSS4.0

CVE-2026-26016 - Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authoriz…

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterodactyl instance, eve…

📅 Published: Feb. 19, 2026, 3:55 p.m. 🔄 Last Modified: April 17, 2026, 6:15 p.m.
Total resulsts: 349182
Page 1550 of 34,919
« previous page » next page
Filters