0.0

CVE-2026-2710 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Feb. 18, 2026, 8:03 p.m. πŸ”„ Last Modified: May 7, 2026, 10:20 p.m.

5.1

CVSS4.0

CVE-2026-2666 - mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit…

πŸ“… Published: Feb. 18, 2026, 8:02 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-2665 - huanzi-qch base-admin JSP Parser SysFileController.java upload unrestricted upload

A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument File results in unrestricted upload. The attack can be init…

πŸ“… Published: Feb. 18, 2026, 8:02 p.m. πŸ”„ Last Modified: April 18, 2026, noon

9.3

CVSS4.0

CVE-2026-23491 - InvoicePlane has Unauthenticated Path Traversal in Guest Controller

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows unauthenticated att…

πŸ“… Published: Feb. 18, 2026, 7:52 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.

0.0

CVE-2026-27201 -

Further research determined the situation described is not a vulnerability.

πŸ“… Published: Feb. 18, 2026, 7:47 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 7:10 p.m.

0.0

CVE-2026-27200 -

Further research determined the situation described is not a vulnerability.

πŸ“… Published: Feb. 18, 2026, 7:47 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 7:11 p.m.

7.8

CVSS3.1

CVE-2026-0875 - MODEL File Parsing Out-of-Bounds Write

A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

πŸ“… Published: Feb. 18, 2026, 7:39 p.m. πŸ”„ Last Modified: May 4, 2026, 2:09 p.m.

7.8

CVSS3.1

CVE-2026-0874 - CATPART File Parsing Out-of-Bounds Write

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

πŸ“… Published: Feb. 18, 2026, 7:38 p.m. πŸ”„ Last Modified: May 4, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-2663 - Alixhan xh-admin-backend Database Query query sql injection

A security vulnerability has been detected in Alixhan xh-admin-backend up to 1.7.0. This issue affects some unknown processing of the file /frontend-api/system-service/api/system/role/query of the component Database Query Handler. Such manipulation of the argument prop leads to sql injection. It is…

πŸ“… Published: Feb. 18, 2026, 7:32 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.

4.8

CVSS4.0

CVE-2026-2662 - FascinatedBox lily lily_emitter.c count_transforms out-of-bounds

A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could …

πŸ“… Published: Feb. 18, 2026, 7:32 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.
Total resulsts: 349182
Page 1587 of 34,919
Β« previous page Β» next page
Filters