快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 358424
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-71057 |
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows atta...
|
HIGH | 8.2 | 2026-02-26 |
未知
|
CVE NVD | |
| CVE-2026-26682 |
An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginC...
|
HIGH | 7.8 | 2026-02-26 |
xjd2020 fastcms
|
CVE NVD | |
| CVE-2026-27809 |
psd-tools: Compression module has unguarded zlib decompression, missing dimension validation, and hardening gaps
|
MEDIUM | 6.8 | 2026-02-25 |
psd-tools psd-tools
psd-tools_project psd-tools
|
CVE NVD | |
| CVE-2026-27808 |
Mailpit is Vulnerable to Server-Side Request Forgery (SSRF) via Link Check API
|
MEDIUM | 5.8 | 2026-02-25 |
axllent mailpit
axllent mailpit
|
CVE NVD | |
| CVE-2026-27804 |
Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
|
CRITICAL | 9.3 | 2026-02-25 |
parse-community parse-server
parse-community parse-server
+2个
|
CVE NVD | |
| CVE-2026-27735 |
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries
|
MEDIUM | 6.4 | 2026-02-25 |
modelcontextprotocol servers
|
CVE NVD | |
| CVE-2026-27711 |
NanaZip UFS Archive Parser Memory Corruption via Unvalidated Directory Record Length
|
MEDIUM | 5.1 | 2026-02-25 |
M2Team NanaZip
M2Team NanaZip
+1个
|
CVE NVD | |
| CVE-2026-27710 |
NanaZip .NET Single-File Parser Integer Underflow Leads to Unbounded Allocation (DoS)
|
MEDIUM | 5.1 | 2026-02-25 |
M2Team NanaZip
M2Team NanaZip
+1个
|
CVE NVD | |
| CVE-2026-27709 |
NanaZip .NET Single-File Manifest Parser Vulnerable to Out-of-Bounds Read via Unchecked RelativePathLength
|
MEDIUM | 5.1 | 2026-02-25 |
M2Team NanaZip
M2Team NanaZip
+1个
|
CVE NVD | |
| CVE-2026-27976 |
Zed Extension Sandbox Escape via Tar Symlink Following
|
HIGH | 8.8 | 2026-02-25 |
zed-industries zed
|
CVE NVD | |
| CVE-2026-27967 |
Symlink Escape in Agent File Tools
|
HIGH | 7.1 | 2026-02-25 |
zed-industries zed
|
CVE NVD | |
| CVE-2026-27800 |
Zed has Zip Slip Path Traversal in Extension Archive Extraction
|
HIGH | 7.4 | 2026-02-25 |
zed-industries zed
zed zed
|
CVE NVD | |
| CVE-2026-27799 |
ImageMagick has a heap Buffer Over-read in its DJVU image format handler
|
MEDIUM | 4.0 | 2026-02-25 |
ImageMagick ImageMagick
ImageMagick ImageMagick
+2个
|
CVE NVD | |
| CVE-2026-27798 |
ImageMagick: Heap Buffer Over-read in WaveletDenoise when processing small images
|
MEDIUM | 4.0 | 2026-02-25 |
ImageMagick ImageMagick
ImageMagick ImageMagick
+2个
|
CVE NVD | |
| CVE-2026-27933 |
Manyfold vulnerable to session hijack via cookie leakage in proxy caches
|
MEDIUM | 6.8 | 2026-02-25 |
manyfold3d manyfold
manyfold manyfold
|
CVE NVD | |
| CVE-2026-27635 |
Manyfold vulnerable to OS command injection via ZIP filename in f3d render
|
HIGH | 7.5 | 2026-02-25 |
manyfold3d manyfold
manyfold manyfold
|
CVE NVD | |
| CVE-2026-27633 |
TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)
|
HIGH | 8.7 | 2026-02-25 |
maximmasiutin TinyWeb
ritlabs tinyweb
|
CVE NVD | |
| CVE-2026-27630 |
TinyWeb vulnerable to Remote Denial of Service via Thread/Connection Exhaustion (Slowloris)
|
HIGH | 8.7 | 2026-02-25 |
maximmasiutin TinyWeb
ritlabs tinyweb
|
CVE NVD | |
| CVE-2026-3209 |
fosrl Pangolin Role verifyApiKeyRoleAccess access control
|
MEDIUM | 5.3 | 2026-02-25 |
fosrl Pangolin
fosrl Pangolin
+2个
|
CVE NVD | |
| CVE-2026-27613 |
CGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)
|
CRITICAL | 10.0 | 2026-02-25 |
maximmasiutin TinyWeb
ritlabs tinyweb
|
CVE NVD |