5.3

CVSS4.0

CVE-2026-25562 - WeKan < 8.19 Attachments Publication Information Disclosure

WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users.

๐Ÿ“… Published: Feb. 7, 2026, 9:57 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:30 a.m.

7.1

CVSS4.0

CVE-2026-25561 - WeKan < 8.19 Attachment Upload Object Relationship Validation Bypass

WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 9:56 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 10:15 p.m.

8.7

CVSS4.0

CVE-2026-25560 - WeKan < 8.19 LDAP Authentication Filter Injection

WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.

๐Ÿ“… Published: Feb. 7, 2026, 9:56 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:30 a.m.

9.3

CVSS4.0

CVE-2026-25858 - macrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP Disclosure

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victimโ€™s telephone number. The password reset flow exposes the one-time passwordโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 9:45 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 9:30 p.m.

8.6

CVSS4.0

CVE-2026-25857 - Tenda G300-F Command Injection via formSetWanDiag

Tenda G300-F router firmware version 16.01.14.2 and prior contain an OS command injection vulnerability in the WAN diagnostic functionality (formSetWanDiag). The implementation constructs a shell command that invokes curl and incorporates attacker-controlled input into the command line without adeqโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 9:41 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 10:15 p.m.

4.8

CVSS4.0

CVE-2025-15564 - Mapnik value.cpp operator divide by zero

A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. The attack needs to be performed locally. The exploit has been disclosed to the public and may be useโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 9:32 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2026, 12:27 a.m.

6.9

CVSS4.0

CVE-2026-2113 - yuan1994 tpadmin WebUploader preview.php deserialization

A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible to be carried out reโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 9:02 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 10:15 p.m.

5.3

CVSS4.0

CVE-2026-2111 - JeecgBoot Retrieval-Augmented Generation edit path traversal

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument filePath can lead to path traversal. The attack can beโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 8:32 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 10:15 p.m.

6.3

CVSS4.0

CVE-2026-2110 - Tasin1025 SwiftBuy login.php excessive authentication

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation results in improper restriction of excessive authentication attempts. Remote exploitโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 8:02 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 1:30 p.m.

5.3

CVSS4.0

CVE-2026-2109 - jsbroks COCO Annotator Delete Category undo improper authorization

A vulnerability was identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file /api/undo/ of the component Delete Category Handler. Such manipulation of the argument ID leads to improper authorization. The attack may be launched remotely. The exploit is publicly โ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 7:32 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 10:15 p.m.
Total resulsts: 348401
Page 1677 of 34,841
ยซ previous page ยป next page
Filters