Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-2634 | 1 Mozilla | 1 Firefox | 2026-02-27 | N/A | 9.8 CRITICAL |
|
Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4.
|
|||||
| CVE-2026-27738 | 2026-02-27 | N/A | N/A | ||
|
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the 21.x branch prior to 21.1.5 and 21.2.0-rc.1. The logic normalizes URL segments by stripping leading slashes; however, it only removes a single leading slash. When an Angular SSR application is deployed behind a proxy that passes the `X-Forwarded-Prefix` header ...
Show More |
|||||
| CVE-2026-27745 | 1 Spip | 1 Interface Traduction Objets | 2026-02-27 | N/A | 8.8 HIGH |
|
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Because fields prefixed with an underscore bypass protection mechanisms and the hidden content is rendered with filtering disabled, an authenticated attacker with editor-level privileges can inject crafted conten ...
Show More |
|||||
| CVE-2026-25129 | 1 Psysh | 1 Psysh | 2026-02-27 | N/A | 6.7 MEDIUM |
|
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim's context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privileg ...
Show More |
|||||
| CVE-2025-69207 | 1 Khoj | 1 Khoj | 2026-02-27 | N/A | 5.4 MEDIUM |
|
Khoj is a self-hostable artificial intelligence app. Prior to 2.0.0-beta.23, an IDOR in the Notion OAuth callback allows an attacker to hijack any user's Notion integration by manipulating the state parameter. The callback endpoint accepts any user UUID without verifying the OAuth flow was initiated by that user, allowing attackers to replace victims' Notion configurations with their own, resulting in data poisoning and unauthorized access to the victim's Khoj search index. This attack requires ...
Show More |
|||||
| CVE-2026-24051 | 1 Linuxfoundation | 1 Opentelemetry-go | 2026-02-27 | N/A | 7.0 HIGH |
|
OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.
|
|||||
| CVE-2025-64712 | 1 Unstructured | 1 Unstructured | 2026-02-27 | N/A | 9.8 CRITICAL |
|
The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary files on the filesystem when processing malicious MSG files with attachments. This issue has been patched in version 0.18.18.
|
|||||
| CVE-2026-24884 | 1 Node-modules | 1 Compressing | 2026-02-27 | N/A | 8.4 HIGH |
|
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outside the intended extraction directory, an attacker can cause subsequent file entries to be written to arbitrary locations on the host file system. Depending on the extractor’s handling of existing files, this behavior may allow overwriting sensitive files or cre ...
Show More |
|||||
| CVE-2026-25505 | 1 Bambuddy | 1 Bambuddy | 2026-02-27 | N/A | 9.8 CRITICAL |
|
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.
|
|||||
| CVE-2026-25128 | 1 Naturalintelligence | 1 Fast-xml-parser | 2026-02-27 | N/A | 7.5 HIGH |
|
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeric entity processing of fast-xml-parser when parsing XML with out-of-range entity code points (e.g., `�` or `�`). This causes the parser to throw an uncaught exception, crashing any application that processes untrusted XML input. Version 5.3.4 fixes the issu ...
Show More |
|||||
| CVE-2026-27628 | 1 Pypdf Project | 1 Pypdf | 2026-02-27 | N/A | 7.5 HIGH |
|
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a workaround, one may apply the patch manually.
|
|||||
| CVE-2026-27583 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27582 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27581 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27580 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27573 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27501 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27500 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27201 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27200 | 2026-02-27 | N/A | N/A | ||
|
Rejected reason: Further research determined the situation described is not a vulnerability.
|
|||||
| CVE-2026-27141 | 2026-02-27 | N/A | 7.5 HIGH | ||
|
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
|
|||||
| CVE-2026-25518 | 1 Cert-manager | 1 Cert-manager | 2026-02-27 | N/A | 5.9 MEDIUM |
|
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. In versions from 1.18.0 to before 1.18.5 and from 1.19.0 to before 1.19.3, the cert-manager-controller performs DNS lookups during ACME DNS-01 processing (for zone discovery and propagation self-checks). By default, these lookups use standard unencrypted DNS. An attacker who can intercept and modify DNS traffic from the c ...
Show More |
|||||
| CVE-2026-25541 | 1 Tokio-rs | 1 Bytes | 2026-02-27 | N/A | 7.5 HIGH |
|
Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() th ...
Show More |
|||||
| CVE-2026-1978 | 1 Kalyan02 | 1 Nanocms | 2026-02-27 | 5.0 MEDIUM | 5.3 MEDIUM |
|
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information Handler. Performing a manipulation results in direct request. It is possible to initiate the attack remotely. The exploit is now public and may be used. You should change the configuration settings.
|
|||||
| CVE-2026-27128 | 1 Craftcms | 1 Craft Cms | 2026-02-27 | N/A | 4.8 MEDIUM |
|
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The `getTokenRoute()` method reads a token’s usage count, checks if it’s within limits, then updates the database in separate non-atomic operations. By sending concurrent requests, an attacker can use a single-use impersonation token multipl ...
Show More |
|||||
| CVE-2026-27126 | 1 Craftcms | 1 Craft Cms | 2026-02-27 | N/A | 4.8 MEDIUM |
|
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field. In order to exploit the vulnerability, an attacker must have an administrator account, and `allow ...
Show More |
|||||
| CVE-2026-26222 | 1 Beyond | 1 Altec Doclink | 2026-02-27 | N/A | 9.8 CRITICAL |
|
Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling, allowing remote attackers to read arbitrary files from the underlying system by specifying local file paths. Additionally, attackers can coerce SMB authentication via UNC paths and write arbitrary fil ...
Show More |
|||||
| CVE-2025-33179 | 1 Nvidia | 5 Cumulus Linux, Dgx Gb200, Gb300 Nvl72 and 2 more | 2026-02-27 | N/A | 8.0 HIGH |
|
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might lead to escalation of privileges.
|
|||||
| CVE-2025-33180 | 1 Nvidia | 5 Cumulus Linux, Dgx Gb200, Gb300 Nvl72 and 2 more | 2026-02-27 | N/A | 8.0 HIGH |
|
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
|
|||||
| CVE-2025-33181 | 1 Nvidia | 5 Cumulus Linux, Dgx Gb200, Gb300 Nvl72 and 2 more | 2026-02-27 | N/A | 7.3 HIGH |
|
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.
|
|||||
| CVE-2026-24241 | 1 Nvidia | 1 Delegated License Service | 2026-02-27 | N/A | 4.3 MEDIUM |
|
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability might lead to information disclosure.
|
|||||
| CVE-2026-27629 | 1 Inventree Project | 1 Inventree | 2026-02-27 | N/A | 5.9 MEDIUM |
|
InvenTree is an Open Source Inventory Management System. Prior to version 1.2.3, insecure server-side templates can be hijacked to expose secure information to the client. When generating custom batch codes, the InvenTree server makes use of a customizable jinja2 template, which can be modified by a staff user to exfiltrate sensitive information or perform code execution on the server. This issue requires access by a user with granted staff permissions, followed by a request to generate a custom ...
Show More |
|||||
| CVE-2026-27632 | 1 Talishar | 1 Talishar | 2026-02-27 | N/A | 2.6 LOW |
|
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar application lacks Cross-Site Request Forgery (CSRF) protections on critical state-changing endpoints, specifically within `SubmitChat.php` and other game interaction handlers. By failing to require unique, unpredictable session tokens, the application allows third-party malicious websites to forge requests on behalf of authenticated users, leading to unauthorized actions within ...
Show More |
|||||
| CVE-2023-53985 | 1 Zippy | 1 Zstore | 2026-02-27 | N/A | 6.1 MEDIUM |
|
Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input parameters. Attackers can submit crafted payloads in manual insertion points to execute arbitrary JavaScript code in victim's browser context.
|
|||||
| CVE-2022-50899 | 1 Osgeo | 1 Geonetwork | 2026-02-27 | N/A | 6.5 MEDIUM |
|
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
|
|||||
| CVE-2026-27744 | 1 Spip | 1 Tickets | 2026-02-27 | N/A | 9.8 CRITICAL |
|
The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering (#ENV**), which disables SPIP output filtering. As a result, an unauthenticated attacker can inject crafted content that is evaluated through SPIP's template processing chain, leading to execution of ...
Show More |
|||||
| CVE-2025-61684 | 1 H2o | 1 Quicly | 2026-02-27 | N/A | 7.5 HIGH |
|
Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using Quicly. Commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e fixes the issue.
|
|||||
| CVE-2026-23736 | 1 Lxsmnsyc | 1 Seroval | 2026-02-27 | N/A | 7.3 HIGH |
|
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This vulnerability affects only JSON deserialization functionality. This issue is fixed in version 1.4.1.
|
|||||
| CVE-2026-23956 | 1 Lxsmnsyc | 1 Seroval | 2026-02-27 | N/A | 7.5 HIGH |
|
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0
and below, overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service). This issue has been fixed in version 1.4.1.
|
|||||
| CVE-2026-23737 | 1 Lxsmnsyc | 1 Seroval | 2026-02-27 | N/A | 7.5 HIGH |
|
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. Exploitation is possible via overriding constant value and error deserialization, allowing indirect access to unsafe JS evaluation. At minimum, attackers need the ability to perform 4 separate requests on the same function, and partial knowledge of ...
Show More |
|||||