6.5

CVSS3.1

CVE-2026-26077 - Discourse doesn't ensure webhooks require a token

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, several webhook endpoints (SendGrid, Mailjet, Mandrill, Postmark, SparkPost) in the `WebhooksController` accepted requests without a valid authentication token when no token was configured. This al…

📅 Published: Feb. 26, 2026, 2:58 p.m. 🔄 Last Modified: Feb. 26, 2026, 2:58 p.m.

8.4

CVSS3.1

CVE-2026-3071 -

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

📅 Published: Feb. 26, 2026, 2:56 p.m. 🔄 Last Modified: Feb. 26, 2026, 2:56 p.m.

8.4

CVSS4.0

CVE-2026-2244 - Sensitive Data Exposure in Google Cloud Vertex AI Workbench

A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No …

📅 Published: Feb. 26, 2026, 2:14 p.m. 🔄 Last Modified: Feb. 26, 2026, 2:14 p.m.

4.8

CVSS4.0

CVE-2026-2680 - Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

📅 Published: Feb. 26, 2026, 12:18 p.m. 🔄 Last Modified: Feb. 26, 2026, 12:18 p.m.

4.8

CVSS4.0

CVE-2026-2679 - Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerName', in 'a3factura-app.wolterskluwer.es/#/incomes/salesInvoices' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

📅 Published: Feb. 26, 2026, 12:18 p.m. 🔄 Last Modified: Feb. 26, 2026, 12:18 p.m.

4.8

CVSS4.0

CVE-2026-2678 - Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/customers' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

📅 Published: Feb. 26, 2026, 12:17 p.m. 🔄 Last Modified: Feb. 26, 2026, 12:17 p.m.

4.8

CVSS4.0

CVE-2026-2677 - Multiple vulnerabilities in A3factura software

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

📅 Published: Feb. 26, 2026, 12:16 p.m. 🔄 Last Modified: Feb. 26, 2026, 12:16 p.m.

7.6

CVSS3.1

CVE-2025-14343 - Reflected XSS in Dokuzsoft Technology's E-Commerce Product

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd. E-Commerce Product allows Reflected XSS.This issue affects E-Commerce Product: through 10122025.

📅 Published: Feb. 26, 2026, 12:06 p.m. 🔄 Last Modified: Feb. 26, 2026, 12:06 p.m.

8.6

CVSS4.0

CVE-2026-1198 - SQL Injection in SIMPLE.ERP

SIMPLE.ERP is vulnerable to the SQL Injection in search functionality in "Obroty na kontach" window. Lack of input validation allows an authenticated attacker to prepare a malicious query to the database that will be executed. This issue was fixed in [email protected]_u06.

📅 Published: Feb. 26, 2026, 11:27 a.m. 🔄 Last Modified: Feb. 26, 2026, 11:27 a.m.

7.3

CVSS4.0

CVE-2025-64999 - Cross-site scripting in HTML logs of Synthetic Monitoring test services

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML logs, which can then be accessed via a crafted phishing link.

📅 Published: Feb. 26, 2026, 10:26 a.m. 🔄 Last Modified: Feb. 26, 2026, 10:26 a.m.
Total resulsts: 334903
Page 2 of 33,491
« previous page » next page
Filters