Latest CVE Feed
-
9.1
CRITICALCVE-2025-1242
The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn Io... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2026-3203
RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Denial of Service
-
4.7
MEDIUMCVE-2026-3202
NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Denial of Service
-
4.7
MEDIUMCVE-2026-3201
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2026-3187
A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoint. Such manipulation leads to unrestricted upload. The ... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2026-2878
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Cryptography
-
9.1
CRITICALCVE-2026-27699
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequenc... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Path Traversal
-
4.3
MEDIUMCVE-2026-27695
zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share the same DynamoDB partition key (`namespace/ENTITY#{id}`). A high-traffic entity can exceed DynamoDB's per-p... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Denial of Service
-
7.1
HIGHCVE-2026-27692
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while pa... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2026-27691
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, signed integer overflow in iccFromCube.cpp during multiplication triggers undefined behavior, potentially causing crashes... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2026-3186
A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the ar... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2026-3185
A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The a... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Authorization
-
2.3
LOWCVE-2026-28196
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk... Read more
Affected Products : teamcity- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2026-28195
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations... Read more
Affected Products : teamcity- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2026-28194
In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow... Read more
Affected Products : teamcity- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2026-28193
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2026-2624
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before ... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Authentication
-
2.6
LOWCVE-2026-21725
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the s... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Race Condition
-
5.9
MEDIUMCVE-2026-0704
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2026-3118
A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, wh... Read more
Affected Products :- Published: Feb. 25, 2026
- Modified: Feb. 25, 2026
- Vuln Type: Injection