5.3

CVSS4.0

CVE-2026-25810 - PlaciPy is Missing Object-Level Authorization in student.submission.routes.ts

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks).

๐Ÿ“… Published: Feb. 9, 2026, 8:48 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

5.3

CVSS4.0

CVE-2026-25876 - PlaciPy is Missing Authorization on Assessment Results Endpoint

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify authentication but fails to enforce object-level authorization (ownership checks). For example, this can be used to return all results for an assessment.

๐Ÿ“… Published: Feb. 9, 2026, 8:48 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

7.5

CVSS3.1

CVE-2026-25791 - Sliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of Service

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored witโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:34 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

5.8

CVSS3.1

CVE-2026-25765 - Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-โ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:30 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1 p.m.

8.8

CVSS3.1

CVE-2026-25761 - Command injection via crafted filenames in Super-linter Action

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull reqโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:27 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

5.8

CVSS4.0

CVE-2026-25740 - Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module

captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localhโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:17 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

7.5

CVSS3.1

CVE-2026-25639 - Axios affected by Denial of Service via __proto__ Key in mergeConfig

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious confโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:11 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

5.8

CVSS3.1

CVE-2026-25528 - LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 8:08 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

8.6

CVSS4.0

CVE-2026-25498 - Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fields.php fails to sanitize user-supplied configuratโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 7:55 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 9:15 p.m.

8.6

CVSS4.0

CVE-2026-25497 - Craft has a GraphQL Asset Mutation Privilege Escalation

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMSโ€™s GraphQL API that allows an authenticated user with write access to one asset volume to escalate their privileโ€ฆ

๐Ÿ“… Published: Feb. 9, 2026, 7:50 p.m. ๐Ÿ”„ Last Modified: Feb. 19, 2026, 7:16 p.m.
Total resulsts: 348556
Page 1670 of 34,856
ยซ previous page ยป next page
Filters