9.3

CVSS4.0

CVE-2026-2550 - EFM iptime A6004MX timepro.cgi commit_vpncli_file_upload unrestricted upload

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was cont…

📅 Published: Feb. 16, 2026, 10:02 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.

4.3

CVSS3.1

CVE-2026-0997 - Mattermost Zoom Plugin channel preference API lacks authorization checks

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitr…

📅 Published: Feb. 16, 2026, 9:58 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.

5.1

CVSS4.0

CVE-2025-59904 - Stored Cross-Site Scripting vulnerability in Kubysoft

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be injected and executed persistently in the context of users accessing the affected resource.

📅 Published: Feb. 16, 2026, 9:55 a.m. 🔄 Last Modified: March 9, 2026, 8:44 p.m.

5.1

CVSS4.0

CVE-2025-59903 - Stored Cross-Site Scripting (XSS) in Kubysoft

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files as visual content, which are then stored on the server and executed in the context of any user accessing the compromis…

📅 Published: Feb. 16, 2026, 9:55 a.m. 🔄 Last Modified: March 9, 2026, 8:01 p.m.

4.3

CVSS3.1

CVE-2026-0998 - Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient …

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary pos…

📅 Published: Feb. 16, 2026, 9:54 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.

10

CVSS3.1

CVE-2026-2577 - Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to h…

📅 Published: Feb. 16, 2026, 9:51 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.

4.8

CVSS4.0

CVE-2025-59905 - Reflected Cross-Site Scripting (XSS) in Kubysoft

Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the vic…

📅 Published: Feb. 16, 2026, 9:49 a.m. 🔄 Last Modified: March 9, 2026, 8:44 p.m.

5.4

CVSS3.1

CVE-2026-0999 - Authentication bypass via userID login when email and username login are disabled

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548

📅 Published: Feb. 16, 2026, 9:47 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.

6.9

CVSS4.0

CVE-2026-2549 - zhanghuanhao LibrarySystem 图书馆管理系统 BookController.java access control

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and…

📅 Published: Feb. 16, 2026, 9:32 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.

5.3

CVSS4.0

CVE-2026-2548 - WAYOS FBM-220G rc sub_40F820 command injection

A flaw has been found in WAYOS FBM-220G 24.10.19. This affects the function sub_40F820 of the file rc. Executing a manipulation of the argument upnp_waniface/upnp_ssdp_interval/upnp_max_age can lead to command injection. The attack can be executed remotely. The vendor was contacted early about this…

📅 Published: Feb. 16, 2026, 9:02 a.m. 🔄 Last Modified: April 17, 2026, 7:15 p.m.
Total resulsts: 349182
Page 1621 of 34,919
« previous page » next page
Filters