Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-1768 — Devolutions Server Permission Cache Poisoning Vulnerability

A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

devolutions_server | Remote | Authorization
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-33181 — NVIDIA Cumulus Linux and NVOS Command Injection Vulnerability

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to esca…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-33180 — NVIDIA Cumulus Linux and NVOS Command Injection Vulnerability

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to esca…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
8.8 HIGH
CVE-2025-33179 — NVIDIA Cumulus Linux and NVOS Privilege Escalation Vulnerability

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could run an unauthorized command. A successful exploit of this vulnerability might l…

Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
7.8 HIGH
CVE-2025-1789 — Genetec Update Service Privilege Escalation

Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

genetec_update_service | Authentication
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
5.8 MEDIUM
CVE-2025-1787 — Genetec Update Service Privilege Escalation

Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin privileged, Windows user could exploit this vulnerability to gain elevated privil…

genetec_update_service | Information Disclosure
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-27468 — Mastodon may allow unconfirmed FASP to make subscriptions

Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval by an administrator. In versions 4.4.0 through 4.4.13 and 4.5.0 through 4.5.6, a…

mastodon | Remote | Denial of Service
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
6.1 MEDIUM
CVE-2026-27156 — NiceGUI has XSS via Code Injection

NiceGUI is a Python-based UI framework. Prior to version 3.8.0, several NiceGUI APIs that execute methods on client-side elements (`Element.run_method()`, `AgGrid.run_grid_method()`, `EChart.run_char…

nicegui | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
10.0 CRITICAL
CVE-2026-26222 — DocLink .NET Remoting Unauthenticated Arbitrary File Read/Write RCE

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.…

altec_doclink | Remote | Information Disclosure
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
6.6 MEDIUM
CVE-2026-25603 — Path Traversal vulnerability in Linksys MR9600, Linksys MX4200

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents of a USB drive partition can be mounted in an arbit…

Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2025-62512 — Piwigo Vulnerable to User Enumeration via Password Reset Endpoint

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to de…

piwigo | Remote | Information Disclosure
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.8 HIGH
CVE-2025-14963 — Trellix HX Agent Local Privilege Escalation (LSE) Vulnerability

A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnera…

endpoint_security | Memory Corruption
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
9.8 CRITICAL
CVE-2026-27590 — Caddy: Unicode case-folding length expansion causes incorrect split_path index (SCRIPT_NA…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and th…

caddy | Remote | Path Traversal
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.9 MEDIUM
CVE-2026-27589 — Caddy vulnerable to cross-origin config application via local admin API /load (caddy)

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`) exposes a state-changing `POST /load` endpoint th…

caddy | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-27588 — Caddy: MatchHost becomes case-sensitive for large host lists (>100), enabling host-based …

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host …

caddy | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-27587 — Caddy: MatchPath %xx (escaped-path) branch skips case normalization, enabling path-based …

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains p…

caddy | Remote | Misconfiguration
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-27586 — Caddy's mTLS client authentication silently fails open when CA certificate file is missin…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to si…

caddy | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.9 MEDIUM
CVE-2026-27585 — Caddy's improper sanitization of glob characters in file matcher may lead to bypassing se…

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the path sanitization routine in file matcher doesn't sanitize backslashes which can lead to bypassing path r…

caddy | Remote | Path Traversal
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-27571 — nats-server websockets are vulnerable to pre-auth memory DoS

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated comp…

nats-server | Remote | Denial of Service
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.6 HIGH
CVE-2025-13776 — Hard-coded database credentials in Finka software

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to rea…

Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
Showing 20 of 5307 Results