6.8

CVSS3.1

CVE-2026-28423 - Statamic Vulnerable to Server-Side Request Forgery via Glide

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP requests to arbitrary…

πŸ“… Published: Feb. 27, 2026, 10:11 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:11 p.m.

9.3

CVSS4.0

CVE-2026-28516 - openDCIM <= 23.04 SQL Injection in Config::UpdateParameter

openDCIM version 23.04, through commit 4467e9c4, contains a SQL injection vulnerability in Config::UpdateParameter. The install.php and container-install.php handlers pass user-supplied input directly into SQL statements using string interpolation without prepared statements or proper input sanitat…

πŸ“… Published: Feb. 27, 2026, 10:11 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:11 p.m.

9.3

CVSS4.0

CVE-2026-28515 - openDCIM <= 23.04 Missing Authorization in install.php

openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user can access this funct…

πŸ“… Published: Feb. 27, 2026, 10:11 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:11 p.m.

2.2

CVSS3.1

CVE-2026-28422 - Vim has stack-buffer-overflow in build_stl_str_hl()

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issue.

πŸ“… Published: Feb. 27, 2026, 10:08 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:08 p.m.

5.3

CVSS3.1

CVE-2026-28421 - Vim has a heap-buffer-overflow and a segmentation fault

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issu…

πŸ“… Published: Feb. 27, 2026, 10:06 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:06 p.m.

4.4

CVSS3.1

CVE-2026-28420 - Vim has Heap-based Buffer Overflow and OOB Read in :terminal

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.

πŸ“… Published: Feb. 27, 2026, 10:04 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:04 p.m.

5.3

CVSS3.1

CVE-2026-28419 - Vim has Heap-based Buffer Underflow in Emacs tags parsing

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding th…

πŸ“… Published: Feb. 27, 2026, 10:02 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 10:02 p.m.

4.4

CVSS3.1

CVE-2026-28418 - Vim has Heap-based Buffer Overflow in Emacs tags parsing

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary.…

πŸ“… Published: Feb. 27, 2026, 9:58 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 9:58 p.m.

4.4

CVSS3.1

CVE-2026-28417 - Vim has OS Command Injection in netrw

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell com…

πŸ“… Published: Feb. 27, 2026, 9:54 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 9:54 p.m.

9.8

CVSS3.1

CVE-2026-28411 - WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)`

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to completely bypass auth…

πŸ“… Published: Feb. 27, 2026, 9:52 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 9:52 p.m.
Total resulsts: 335179
Page 2 of 33,518
Β« previous page Β» next page
Filters