7.3

CVSS4.0

CVE-2025-14340 - Admin Account Takeover via malicious URL payload

Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0,Β <6.34.0,Β <7.2026.1 allows an attacker to mislead the administrator to change the admin password via URL Payload.

πŸ“… Published: Feb. 18, 2026, 1:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2026-2654 - huggingface smolagents LocalPythonExecutor requests.post server-side request forgery

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made availa…

πŸ“… Published: Feb. 18, 2026, 1:32 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-1441 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker …

πŸ“… Published: Feb. 18, 2026, 1:14 p.m. πŸ”„ Last Modified: April 18, 2026, noon

5.3

CVSS4.0

CVE-2026-1440 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker …

πŸ“… Published: Feb. 18, 2026, 1:13 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-1439 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker …

πŸ“… Published: Feb. 18, 2026, 1:13 p.m. πŸ”„ Last Modified: April 17, 2026, 6:45 p.m.

5.3

CVSS4.0

CVE-2026-1438 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker …

πŸ“… Published: Feb. 18, 2026, 1:13 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 p.m.

5.3

CVSS4.0

CVE-2026-1437 - Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and escaping in HTML output. Several endpoints include segments of the URL directly in the response without applying output encoding, allowing an attacker …

πŸ“… Published: Feb. 18, 2026, 1:12 p.m. πŸ”„ Last Modified: April 18, 2026, 12:15 p.m.

7.1

CVSS4.0

CVE-2026-1436 - Improper Access Control (IDOR) vulnerability in Graylog Web Interface

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can access other user's profiles without proper authorization checks. Exploiting this vulnerability allows valid users of the system to be listed and sensitive…

πŸ“… Published: Feb. 18, 2026, 1:09 p.m. πŸ”„ Last Modified: April 17, 2026, 7 p.m.

9.3

CVSS4.0

CVE-2026-1435 - Incorrect management of session invalidation vulnerability in Graylog Web Interface

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identifiers, wh…

πŸ“… Published: Feb. 18, 2026, 1:08 p.m. πŸ”„ Last Modified: April 17, 2026, 7 p.m.

6.5

CVSS3.1

CVE-2026-1317 - WP Import – Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injec…

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient escaping on the `file_name` parameter which is stored in the database during file upload and later used in raw SQL quer…

πŸ“… Published: Feb. 18, 2026, 12:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346671
Page 1342 of 34,668
Β« previous page Β» next page
Filters