8.8

CVSS3.1

CVE-2026-25761 - Command injection via crafted filenames in Super-linter Action

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull req…

📅 Published: Feb. 9, 2026, 8:27 p.m. 🔄 Last Modified: April 17, 2026, 9:15 p.m.

5.8

CVSS4.0

CVE-2026-25740 - Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module

captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localh…

📅 Published: Feb. 9, 2026, 8:17 p.m. 🔄 Last Modified: April 17, 2026, 9:15 p.m.

7.5

CVSS3.1

CVE-2026-25639 - Axios affected by Denial of Service via __proto__ Key in mergeConfig

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious conf…

📅 Published: Feb. 9, 2026, 8:11 p.m. 🔄 Last Modified: April 17, 2026, 9:15 p.m.

5.8

CVSS3.1

CVE-2026-25528 - LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to ex…

📅 Published: Feb. 9, 2026, 8:08 p.m. 🔄 Last Modified: April 17, 2026, 9:15 p.m.

8.6

CVSS4.0

CVE-2026-25498 - Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fields.php fails to sanitize user-supplied configurat…

📅 Published: Feb. 9, 2026, 7:55 p.m. 🔄 Last Modified: April 17, 2026, 9:15 p.m.

8.6

CVSS4.0

CVE-2026-25497 - Craft has a GraphQL Asset Mutation Privilege Escalation

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write access to one asset volume to escalate their privile…

📅 Published: Feb. 9, 2026, 7:50 p.m. 🔄 Last Modified: Feb. 19, 2026, 7:16 p.m.

4.8

CVSS4.0

CVE-2026-25496 - Craft has a stored XSS in Number Prefix & Suffix Fields

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |md|raw Twig filter without proper escaping, allow…

📅 Published: Feb. 9, 2026, 7:45 p.m. 🔄 Last Modified: Feb. 19, 2026, 7:17 p.m.

8.7

CVSS4.0

CVE-2026-25495 - Craft has a SQL Injection in Element Indexes via criteria[orderBy]

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (JSON body). The application fails to sanitize this input befo…

📅 Published: Feb. 9, 2026, 7:42 p.m. 🔄 Last Modified: April 18, 2026, 1 p.m.

6.9

CVSS4.0

CVE-2026-25494 - Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP addresses. However, alternative IP notations (hexadecimal, mixed) a…

📅 Published: Feb. 9, 2026, 7:41 p.m. 🔄 Last Modified: Feb. 19, 2026, 7:17 p.m.

6.9

CVSS4.0

CVE-2026-25493 - Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An attacker can bypass…

📅 Published: Feb. 9, 2026, 7:36 p.m. 🔄 Last Modified: April 17, 2026, 9:30 p.m.
Total resulsts: 349182
Page 1733 of 34,919
« previous page » next page
Filters