6.9

CVSS4.0

CVE-2026-3185 - feiyuchuixue sz-boot-parent API Endpoint sys-message authorization

A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The attack can be launched remotely. The exploit …

πŸ“… Published: Feb. 25, 2026, 1:32 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 1:32 p.m.

2.3

CVSS3.1

CVE-2026-28196 -

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

πŸ“… Published: Feb. 25, 2026, 12:57 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:57 p.m.

4.3

CVSS3.1

CVE-2026-28195 -

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

πŸ“… Published: Feb. 25, 2026, 12:57 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:57 p.m.

4.3

CVSS3.1

CVE-2026-28194 -

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

πŸ“… Published: Feb. 25, 2026, 12:57 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:57 p.m.

8.8

CVSS3.1

CVE-2026-28193 -

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

πŸ“… Published: Feb. 25, 2026, 12:57 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:57 p.m.

9.8

CVSS3.1

CVE-2026-2624 - Authentication Bypass in ePati's Antikor NGFW

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.

πŸ“… Published: Feb. 25, 2026, 12:39 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:39 p.m.

2.6

CVSS3.1

CVE-2026-21725 - Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deleti…

πŸ“… Published: Feb. 25, 2026, 12:35 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:35 p.m.

5.9

CVSS4.0

CVE-2026-0704 -

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

πŸ“… Published: Feb. 25, 2026, 12:22 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 12:22 p.m.

0.0

CVE-2026-3197 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Feb. 25, 2026, 11:35 a.m. πŸ”„ Last Modified: Feb. 25, 2026, 2:01 p.m.

6.5

CVSS3.1

CVE-2026-3118 - Rhdh: graphql injection leading to platform-wide denial of service (dos) in rh developer hub orches…

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, which disrupts backend query processing. This …

πŸ“… Published: Feb. 25, 2026, 11:25 a.m. πŸ”„ Last Modified: Feb. 25, 2026, 11:25 a.m.
Total resulsts: 334681
Page 2 of 33,469
Β« previous page Β» next page
Filters