8.8

CVSS3.1

CVE-2026-27483 - MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the "Up…

πŸ“… Published: Feb. 24, 2026, 2 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

9.2

CVSS3.1

CVE-2026-27208 - api-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root Execution

bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privileges within the container, potentially leading to a contain…

πŸ“… Published: Feb. 24, 2026, 1:52 p.m. πŸ”„ Last Modified: April 16, 2026, 4:30 p.m.

9.8

CVSS3.1

CVE-2026-2807 - Memory safety bugs fixed in Firefox 148 and Thunderbird 148

Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.1

CVSS3.1

CVE-2026-2806 - Uninitialized memory in the Graphics: Text component

Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

5.4

CVSS3.1

CVE-2026-2804 - Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2026-2805 - Invalid pointer in the DOM: Core & HTML component

Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

7.5

CVSS3.1

CVE-2026-2803 - Information disclosure, mitigation bypass in the Settings UI component

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

4.2

CVSS3.1

CVE-2026-2802 - Race condition in the JavaScript: GC component

Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

9.8

CVSS3.1

CVE-2026-2800 - Spoofing issue in the WebAuthn component in Firefox for Android

Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.

7.5

CVSS3.1

CVE-2026-2801 - Incorrect boundary conditions in the JavaScript: WebAssembly component

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

πŸ“… Published: Feb. 24, 2026, 1:33 p.m. πŸ”„ Last Modified: April 15, 2026, 5 p.m.
Total resulsts: 347742
Page 1319 of 34,775
Β« previous page Β» next page
Filters