cve.li

Recent

CVE-2026-28402CWE-354

nimiq/core-rs-albatross's nimiq-blockchain missing proposal body root verification

Published 2026-02-27 by GitHub_M

CVE-2026-28400CWE-749

Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint

Published 2026-02-27 by GitHub_M

CVE-2026-28355CWE-79

"PWA" Canarytoken Vulnerable to Stored Self Cross-Site Scripting

Published 2026-02-27 by GitHub_M

CVE-2026-28352CWE-306

Indico missing access check in event series management API

Published 2026-02-27 by GitHub_M

CVE-2026-28351CWE-400

Manipulated RunLengthDecode streams can exhaust RAM

Published 2026-02-27 by GitHub_M

CVE-2026-28338CWE-79

PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages

Published 2026-02-27 by GitHub_M

CVE-2026-28288CWE-204

Dify has a user enumeration issue

Published 2026-02-27 by GitHub_M

CVE-2026-28272CWE-79

Kiteworks Email Protection Gateway has a Cross-site Scripting vulnerability

Published 2026-02-27 by GitHub_M

CVE-2026-28271CWE-350CWE-918

Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)

Published 2026-02-27 by GitHub_M

CVE-2026-28270CWE-434

Kiteworks Core has an Unrestricted Upload of File with Dangerous Type

Published 2026-02-27 by GitHub_M

Load more ↓