7.5

CVSS3.1

CVE-2026-27850 - Improper verification in Linksys MR9600, Linksys MX4200

Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

πŸ“… Published: Feb. 25, 2026, 4:58 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

8.3

CVSS4.0

CVE-2026-25554 - OpenSIPS 3.1 <= 3.6.4 auth_jwt SQL Injection Enables JWT Authentication Bypass

OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_authorize() function in modules/auth_jwt/authorize.c when db_mode is enabled and a SQL database backend is used. The function extracts the tag claim from a…

πŸ“… Published: Feb. 25, 2026, 4:54 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

6.6

CVSS3.1

CVE-2026-27794 - LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution

LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseCache` and opt nodes into caching via `CachePolicy`. Prior to…

πŸ“… Published: Feb. 25, 2026, 4:53 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

9.2

CVSS4.0

CVE-2026-27739 - Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forgery (SSRF) vulnerability in the Angular SSR request handling pipeline. The vulnerability exists because Angular’s internal URL reconst…

πŸ“… Published: Feb. 25, 2026, 4:47 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 p.m.

6.9

CVSS4.0

CVE-2026-27738 - Angular SSR has an Open Redirect via X-Forwarded-Prefix

The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the 21.x branch prior to 21.1.5 and 21.2.0-rc.1. The logic norm…

πŸ“… Published: Feb. 25, 2026, 4:40 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

2.3

CVSS4.0

CVE-2026-3193 - Chia Blockchain send_transaction cross-site request forgery

A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered dif…

πŸ“… Published: Feb. 25, 2026, 4:32 p.m. πŸ”„ Last Modified: April 16, 2026, 4:15 p.m.

6.1

CVSS3.1

CVE-2026-27736 - BigBlueButton has Open Redirect vulnerability in ApiController

BigBlueButton is an open-source virtual classroom. In versions on the 3.x branch prior to 3.0.20, the string received with errorRedirectUrl lacks validation, using it directly in the respondWithRedirect function leads to an Open Redirect vulnerability. BigBlueButton 3.0.20 patches the issue. No kno…

πŸ“… Published: Feb. 25, 2026, 4:27 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

7.4

CVSS3.1

CVE-2026-20033 - Cisco NX-OS Software Denial of Service Vulnerability

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker …

πŸ“… Published: Feb. 25, 2026, 4:26 p.m. πŸ”„ Last Modified: April 17, 2026, 3:15 p.m.

7.7

CVSS3.1

CVE-2026-20048 - Cisco NX-OS Software SNMP Denial of Service Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing whe…

πŸ“… Published: Feb. 25, 2026, 4:26 p.m. πŸ”„ Last Modified: April 18, 2026, 10:45 a.m.

6.7

CVSS3.1

CVE-2026-20099 - Cisco UCS Manager and FXOS Software Command Injection Vulnerability

A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco&nbsp;UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to&nbsp;root.&nbsp; This …

πŸ“… Published: Feb. 25, 2026, 4:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347814
Page 1304 of 34,782
Β« previous page Β» next page
Filters