4.3

CVSS3.1

CVE-2026-20139 - Client-Side Denial of Service (DoS) through ''/splunkd/__raw/services/authentication/users/username…

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload into the `real…

📅 Published: Feb. 18, 2026, 4:45 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

6.8

CVSS3.1

CVE-2026-20144 - Sensitive Information Disclosure in ''_internal'' index in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk _internal index cou…

📅 Published: Feb. 18, 2026, 4:45 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

4.3

CVSS3.1

CVE-2026-20141 - Improper Access Control in Splunk Monitoring Console App

In Splunk Enterprise versions below 10.0.2, 10.0.3, 9.4.8, and 9.3.9, a low-privileged user who does not hold the "admin" Splunk role could access the Splunk Monitoring Console App endpoints due to an improper access control. This could lead to a sensitive information disclosure.<br><br>The Monitor…

📅 Published: Feb. 18, 2026, 4:45 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

3.5

CVSS3.1

CVE-2026-20137 - Risky Commands Safeguards Bypass through preloaded Data Models due to Path Traversal vulnerability …

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk roles could bypass the SPL safeguards for risky comma…

📅 Published: Feb. 18, 2026, 4:45 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

4.8

CVSS4.0

CVE-2026-2657 - wren-lang wren Error Message wren_compiler.c printError stack-based overflow

A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclose…

📅 Published: Feb. 18, 2026, 4:32 p.m. 🔄 Last Modified: April 18, 2026, noon

4.3

CVSS3.1

CVE-2026-2230 - Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbi…

The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level …

📅 Published: Feb. 18, 2026, 4:28 p.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

8.7

CVSS4.0

CVE-2026-2507 - BIG-IP TMM Vulnerability

When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

📅 Published: Feb. 18, 2026, 3:55 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

9.5

CVSS4.0

CVE-2025-15579 - An Insecure Deserialization vulnerability has been discovered in OpenText™ Directory Services.

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 be…

📅 Published: Feb. 18, 2026, 2:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-61982 -

An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM simulation file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

📅 Published: Feb. 18, 2026, 2:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2026-2656 - ChaiScript type_info.hpp bare_equal use after free

A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use after free. The attack requires local access. The attack's complexity is rated as high. The exploitabil…

📅 Published: Feb. 18, 2026, 2:32 p.m. 🔄 Last Modified: April 18, 2026, noon
Total resulsts: 349182
Page 1589 of 34,919
« previous page » next page
Filters