CVE ID : CVE-2026-27976 Published : Feb. 26, 2026, 12:16 a.m. | 32 minutes ago Description : Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the…
CVE-2026-27818 – TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist
CVE ID : CVE-2026-27818 Published : Feb. 26, 2026, 12:16 a.m. | 32 minutes ago Description : TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers….
CVE-2026-27812 – Sub2API Vulnerable to Password Reset Poisoning via Host Header Trust Issue, Leading to Account Takeover
CVE ID : CVE-2026-27812 Published : Feb. 26, 2026, 12:16 a.m. | 32 minutes ago Description : Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI…
CVE-2026-27804 – Parse Server: Account takeover via JWT algorithm confusion in Google auth adapter
CVE ID : CVE-2026-27804 Published : Feb. 26, 2026, 12:16 a.m. | 32 minutes ago Description : Parse Server is an open source backend that can be deployed to any infrastructure that can…
CVE-2026-27633 – TinyWeb has Unbounded Content-Length Memory Exhaustion (DoS)
CVE ID : CVE-2026-27633 Published : Feb. 26, 2026, 12:16 a.m. | 32 minutes ago Description : TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version…
CVE-2026-27593 – Statamic is vulnerable to account takeover via password reset link injection
CVE ID : CVE-2026-27593 Published : Feb. 24, 2026, 10:16 p.m. | 2 hours, 32 minutes ago Description : Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3…
CVE-2026-24443 – EventSentry < 6.0.1.20 Web Reports Unverified Password Change
CVE ID : CVE-2026-24443 Published : Feb. 24, 2026, 9:16 p.m. | 3 hours, 32 minutes ago Description : EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management functionality…
CVE-2026-22553 – InSAT MasterSCADA BUK-TS OS Command Injection
CVE ID : CVE-2026-22553 Published : Feb. 24, 2026, 9:16 p.m. | 3 hours, 32 minutes ago Description : All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field…
CVE-2026-21410 – InSAT MasterSCADA BUK-TS SQL Injection
CVE ID : CVE-2026-21410 Published : Feb. 24, 2026, 9:16 p.m. | 3 hours, 32 minutes ago Description : InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users…
CVE-2026-26342 – Tattile Smart+ / Vega / Basic <= 1.181.5 Insufficient Session Token Expiration
CVE ID : CVE-2026-26342 Published : Feb. 24, 2026, 8:27 p.m. | 4 hours, 20 minutes ago Description : Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication…