4.8

CVSS4.0

CVE-2026-2657 - wren-lang wren Error Message wren_compiler.c printError stack-based overflow

A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclose…

📅 Published: Feb. 18, 2026, 4:32 p.m. 🔄 Last Modified: April 18, 2026, noon

4.3

CVSS3.1

CVE-2026-2230 - Booking Calendar <= 10.14.14 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbi…

The Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.14.14 via the handle_ajax_save function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level …

📅 Published: Feb. 18, 2026, 4:28 p.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

8.7

CVSS4.0

CVE-2026-2507 - BIG-IP TMM Vulnerability

When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

📅 Published: Feb. 18, 2026, 3:55 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

9.5

CVSS4.0

CVE-2025-15579 - An Insecure Deserialization vulnerability has been discovered in OpenText™ Directory Services.

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 be…

📅 Published: Feb. 18, 2026, 2:57 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-61982 -

An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM simulation file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

📅 Published: Feb. 18, 2026, 2:38 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2026-2656 - ChaiScript type_info.hpp bare_equal use after free

A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use after free. The attack requires local access. The attack's complexity is rated as high. The exploitabil…

📅 Published: Feb. 18, 2026, 2:32 p.m. 🔄 Last Modified: April 18, 2026, noon

6.1

CVSS3.1

CVE-2026-1404 - Ultimate Member <= 2.11.1 - Reflected Cross-Site Scripting via Filter Parameters

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the filter parameters (e.g., 'filter_first_name') in all versions up to, and including, 2.11.1 due to insuffici…

📅 Published: Feb. 18, 2026, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2026-1426 - Advanced AJAX Product Filters <= 3.1.9.6 - Authenticated (Author+) PHP Object Injection via Live Co…

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated at…

📅 Published: Feb. 18, 2026, 2:24 p.m. 🔄 Last Modified: April 15, 2026, 8:30 p.m.

4.3

CVSS3.1

CVE-2026-27100 - org.jenkins-ci.main/jenkins-core: Jenkins: Information disclosure via unauthorized access to build …

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, an…

📅 Published: Feb. 18, 2026, 2:17 p.m. 🔄 Last Modified: April 17, 2026, 6:45 p.m.

8

CVSS3.1

CVE-2026-27099 - org.jenkins-ci.main/jenkins-core: Jenkins: Stored Cross-site Scripting (XSS) via unescaped user-pro…

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or A…

📅 Published: Feb. 18, 2026, 2:17 p.m. 🔄 Last Modified: April 18, 2026, noon
Total resulsts: 346692
Page 1341 of 34,670
« previous page » next page
Filters