漏洞列表 358915
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-24004
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint
LOW 1.7 2026-02-26
fleetdm fleet fleetdm fleet
CVE NVD
CVE-2026-27975
Ajenti has a potential Remote Code Execution
HIGH 8.1 2026-02-26
ajenti ajenti ajenti ajenti
CVE NVD
CVE-2026-1779
User Registration & Membership <= 5.1.2 - Authentication Bypass
HIGH 8.1 2026-02-26
wpeverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
CVE NVD
CVE-2026-2356
User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
MEDIUM 5.3 2026-02-26
wpeverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
CVE NVD
CVE-2026-27974
Audiobooksheld VUlnerable to Stored XSS in WrappingMarquee.js via Audiobook Metadata (Mobile App Audio Player)
MEDIUM 4.8 2026-02-26
advplyr audiobookshelf-app
CVE NVD
CVE-2026-27963
Audiobookshelf has Stored XSS in Tooltip.vue via Audiobook Metadata
MEDIUM 4.8 2026-02-26
advplyr audiobookshelf audiobookshelf audiobookshelf
CVE NVD
CVE-2026-27973
Audiobookshelf has Stored XSS in ItemSearchCard.vue via Audiobook Metadata (Search Results on Mobile App)
MEDIUM 4.0 2026-02-26
advplyr audiobookshelf advplyr audiobookshelf-app
CVE NVD
CVE-2026-27970
Angular i18n vulnerable to Cross-Site Scripting (XSS)
HIGH 7.6 2026-02-26
angular angular angular angular +5个
CVE NVD
CVE-2026-27968
Packistry accepts expired access tokens
MEDIUM 4.3 2026-02-26
packistry packistry packistryphp packistry
CVE NVD
CVE-2026-27966
Langflow has Remote Code Execution in CSV Agent
CRITICAL 9.8 2026-02-26
langflow-ai langflow langflow langflow
CVE NVD
CVE-2026-27969
Vitess users with backup storage access can write to arbitrary file paths on restore
CRITICAL 9.3 2026-02-26
vitessio vitess vitessio vitess +1个
CVE NVD
CVE-2026-27965
Vitess users with backup storage access can gain unauthorized access to production deployment environments
HIGH 8.4 2026-02-26
vitessio vitess vitessio vitess +1个
CVE NVD
CVE-2026-27959
Koa has Host Header Injection via `ctx.hostname`
HIGH 7.5 2026-02-26
koajs koa koajs koa +1个
CVE NVD
CVE-2026-27954
LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and transferchat endpoints
MEDIUM 4.9 2026-02-26
LiveHelperChat livehelperchat livehelperchat live_helper_chat
CVE NVD
CVE-2026-27961
Agenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allows RCE
HIGH 8.8 2026-02-26
Agenta-AI agenta agentatech agenta
CVE NVD
CVE-2026-27952
Agenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)
HIGH 8.8 2026-02-26
Agenta-AI agenta-api agentatech agenta
CVE NVD
CVE-2026-27948
Copyparty vulnerable to eflected cross-site scripting via setck parameter
MEDIUM 5.4 2026-02-26
9001 copyparty 9001 copyparty
CVE NVD
CVE-2026-27943
OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership
MEDIUM 6.5 2026-02-26
openemr openemr open-emr openemr
CVE NVD
CVE-2026-2499
Custom Logo <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via Logo Path Setting
MEDIUM 4.4 2026-02-26
tgrk Custom Logo
CVE NVD
CVE-2026-2029
Livemesh Addons for Beaver Builder <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes
MEDIUM 6.4 2026-02-26
livemesh Livemesh Addons for Beaver Builder
CVE NVD