7.5

CVSS3.1

CVE-2026-21878 - BACnet Stack Improperly Limits Pathnames to a Restricted Directory

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary directori…

πŸ“… Published: Feb. 13, 2026, 6:10 p.m. πŸ”„ Last Modified: April 17, 2026, 8 p.m.

5.5

CVSS3.1

CVE-2026-21870 - The BACnet Protocol Stack library has an Off-by-one Stack-based Buffer Overflow in tokenizer_string

BACnet Protocol Stack library provides a BACnet application layer, network layer and media access (MAC) layer communications services. In 1.4.2, 1.5.0.rc2, and earlier, an off-by-one stack-based buffer overflow in the ubasic interpreter causes a crash (SIGABRT) when processing string literals longe…

πŸ“… Published: Feb. 13, 2026, 5:58 p.m. πŸ”„ Last Modified: April 17, 2026, 8 p.m.

8.1

CVSS3.1

CVE-2026-26268 - Cursor sandbox escape via Git hooks

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time th…

πŸ“… Published: Feb. 13, 2026, 4:54 p.m. πŸ”„ Last Modified: April 17, 2026, 8 p.m.

5.8

CVSS4.0

CVE-2025-1790 -

Local privilege escalation in Genetec Sipelia Plugin. An authenticated low-privileged Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

πŸ“… Published: Feb. 13, 2026, 4:45 p.m. πŸ”„ Last Modified: April 26, 2026, 6:49 p.m.

5.3

CVSS4.0

CVE-2026-26226 - beautiful-mermaid < 0.1.3 SVG Attribute Injection

beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams. User-controlled values from Mermaid style and classDef directives are interpolated into SVG attribute values without pr…

πŸ“… Published: Feb. 13, 2026, 4:35 p.m. πŸ”„ Last Modified: April 17, 2026, 8 p.m.

5.4

CVSS4.0

CVE-2026-2026 - Improper Access Control Allows Denial of Service

A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.

πŸ“… Published: Feb. 13, 2026, 4:14 p.m. πŸ”„ Last Modified: April 17, 2026, 8 p.m.

9.3

CVSS4.0

CVE-2026-26221 - Hyland OnBase Timer Services Unauthenticated .NET Remoting RCE

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attacker who can reach the service can send crafted .NET Remoting requests to default HTTP channel endpoints on TCP/8900 (e.g., TimerServiceAPI.rem and Time…

πŸ“… Published: Feb. 13, 2026, 3:21 p.m. πŸ”„ Last Modified: April 15, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2026-25531 - Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions fo…

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, The fix for CVE-2023-33968 is incomplete. The TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects, allowing authenticated users to duplicate tasks into pro…

πŸ“… Published: Feb. 13, 2026, 3:04 p.m. πŸ”„ Last Modified: April 18, 2026, 12:45 p.m.

5.1

CVSS4.0

CVE-2026-1578 - HP App – Potential Cross-Site Scripting

HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.

πŸ“… Published: Feb. 13, 2026, 2:56 p.m. πŸ”„ Last Modified: April 17, 2026, 8 p.m.

8.3

CVSS3.1

CVE-2026-1619 - IDOR in Universal Sotware's FlexCity/Kiosk

Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploitation of Trusted Identifiers.This issue affects FlexCity/Kiosk: from 1.0 before 1.0.36.

πŸ“… Published: Feb. 13, 2026, 1:20 p.m. πŸ”„ Last Modified: April 18, 2026, 12:45 p.m.
Total resulsts: 349182
Page 1646 of 34,919
Β« previous page Β» next page
Filters