6.3

CVSS4.0

CVE-2026-3192 - Chia Blockchain RPC Credential rpc_server_base.py _authenticate improper authentication

A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. The attack is possible to be carried out remotely. The attack…

📅 Published: Feb. 25, 2026, 4:02 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

2.3

CVSS4.0

CVE-2026-3189 - feiyuchuixue sz-boot-parent download server-side request forgery

A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code of the file /api/admin/common/files/download. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. Attacks of…

📅 Published: Feb. 25, 2026, 4:02 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

8.9

CVSS4.0

CVE-2026-27727 - mchange-commons-java: Remote Code Execution via JNDI Reference Resolution

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an a…

📅 Published: Feb. 25, 2026, 4:01 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

7.7

CVSS3.1

CVE-2026-27706 - Plane Vulnerable to Full Read SSRF via Favicon Fetching in "Add Link" Feature

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the inter…

📅 Published: Feb. 25, 2026, 3:56 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

4.9

CVSS4.0

CVE-2026-27705 - Plane Vulnerable to Cross-Workspace/Cross-Project Asset Modification via IDOR in ProjectAssetEndpoi…

Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) performs a global asset lookup using only the asset ID (`pk`) via `FileAsset.objects.get(id=pk)`, without verifying that th…

📅 Published: Feb. 25, 2026, 3:51 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

2.7

CVSS4.0

CVE-2026-22866 - ENS DNSSEC Oracle Vulnerable to RSA Signature Forgery via Missing PKCS#1 v1.5 Padding Validation

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only …

📅 Published: Feb. 25, 2026, 3:47 p.m. 🔄 Last Modified: April 17, 2026, 3:15 p.m.

7.5

CVSS3.1

CVE-2026-27730 - esm.sh has SSRF localhost/private-network bypass in `/http(s)` module route

esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. The service tries to block localhost/internal targets, but the validation is based on hostname string checks and can be …

📅 Published: Feb. 25, 2026, 3:37 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

8.7

CVSS4.0

CVE-2025-50180 - esm.sh is vulnerable to full-response SSRF

esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.

📅 Published: Feb. 25, 2026, 3:32 p.m. 🔄 Last Modified: Feb. 27, 2026, 6:22 p.m.

5.3

CVSS4.0

CVE-2026-3188 - feiyuchuixue sz-boot-parent API templates path traversal

A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the file /api/admin/common/download/templates of the component API. Performing a manipulation of the argument templateName results in path traversal. Remote exploitation of the attac…

📅 Published: Feb. 25, 2026, 3:32 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

9.3

CVSS4.0

CVE-2025-1242 - Administrative Credentials Can Be Extracted Through Gardyn API Responses

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn IoT Hub exposing connected devices to maliciou…

📅 Published: Feb. 25, 2026, 3:21 p.m. 🔄 Last Modified: April 22, 2026, 5:54 p.m.
Total resulsts: 347810
Page 1306 of 34,781
« previous page » next page
Filters