0.0

CVE-2026-26995 -

Further research determined the issue is an external dependency vulnerability.

πŸ“… Published: Feb. 17, 2026, 1:41 a.m. πŸ”„ Last Modified: Feb. 20, 2026, 3 a.m.

8.8

CVSS3.1

CVE-2026-26736 - Stack‑Based Buffer Overflow in TOTOLINK A3002RU_V3 IPv6 Setup

TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 17, 2026, 7 p.m.

7.1

CVSS3.1

CVE-2025-70846 -

lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field password.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-70397 -

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: Feb. 19, 2026, 6:24 p.m.

3.5

CVSS3.1

CVE-2024-55271 -

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 4:06 p.m.

7.5

CVSS3.1

CVE-2025-65753 -

An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-55270 -

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 4:23 p.m.

8.7

CVSS3.1

CVE-2025-67905 -

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an a…

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2025-67102 -

A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands via the entity parameter.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: April 3, 2026, 11:34 a.m.

5.7

CVSS3.1

CVE-2025-70829 -

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

πŸ“… Published: Feb. 17, 2026, midnight πŸ”„ Last Modified: Feb. 23, 2026, 1:17 p.m.
Total resulsts: 349182
Page 1614 of 34,919
Β« previous page Β» next page
Filters