6.9

CVSS4.0

CVE-2026-25242 - Gogs allows unauthenticated file uploads

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the server via /releases/attachments and /issues/attachme…

📅 Published: Feb. 19, 2026, 2:28 a.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

7.1

CVSS4.0

CVE-2026-25232 - Gogs has a Protected Branch Deletion Bypass in Web Interface

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request, completely bypassing th…

📅 Published: Feb. 19, 2026, 2:25 a.m. 🔄 Last Modified: April 18, 2026, noon

5.3

CVSS4.0

CVE-2026-2692 - CoCoTeaNet CyreneAdmin Image getAvatar path traversal

A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component Image Handler. Performing a manipulation of the argument Avatar results in path traversal. The attack can be initiated remotely. The exploit has been…

📅 Published: Feb. 19, 2026, 2:02 a.m. 🔄 Last Modified: April 18, 2026, noon

5.1

CVSS4.0

CVE-2026-25120 - Gogs Allows Cross-Repository Comment Deletion via DeleteComment

Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any other repository by supplying arbitrary comment IDs…

📅 Published: Feb. 19, 2026, 1:59 a.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

7.8

CVSS3.1

CVE-2025-4960 - macOS Local Privilege Escalation via Improper Authorization Handling in EPSON Printer Controller In…

The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorizat…

📅 Published: Feb. 19, 2026, 1:37 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2026-2691 - itsourcecode Event Management System manage_register.php sql injection

A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been di…

📅 Published: Feb. 19, 2026, 1:32 a.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

3.7

CVSS3.1

CVE-2026-24764 - OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-drive…

📅 Published: Feb. 19, 2026, 1:10 a.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.

6.9

CVSS4.0

CVE-2026-2690 - itsourcecode Event Management System Admin Login ajax.php sql injection

A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Admin Login. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack…

📅 Published: Feb. 19, 2026, 1:02 a.m. 🔄 Last Modified: April 18, 2026, noon

6.9

CVSS4.0

CVE-2026-2689 - itsourcecode Event Management System manage_booking.php sql injection

A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

📅 Published: Feb. 19, 2026, 12:32 a.m. 🔄 Last Modified: April 18, 2026, 6 p.m.

9.3

CVSS4.0

CVE-2026-2686 - SECCN Dingcheng G10 session_login.cgi qq os command injection

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed…

📅 Published: Feb. 19, 2026, 12:02 a.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.
Total resulsts: 349182
Page 1579 of 34,919
« previous page » next page
Filters