Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-3066 — HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection

A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformU…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27461 — Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE …

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded a…

pimcore | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.1 HIGH
CVE-2026-3091 — Synology Presto Client DLL Injection Vulnerability

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in adv…

presto_client | Path Traversal
Feb 24, 2026 Mar 04, 2026
Feb 24, 2026
Mar 04, 2026
8.8 HIGH
CVE-2026-3065 — HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult …

A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the component Cloud Task Dry-run. Performin…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3064 — HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection

A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreateService.java of the component Cloud Task Scheduler…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3057 — a54552239 pearProjectApi Backend Task.php dateTotalForProject sql injection

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Inter…

pearprojectapi | Remote | Injection
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2026-3054 — Alinto SOGo cross site scripting

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotel…

sogo | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27129 — Cloud Metadata SSRF Protection Bypass via IPv6 Resolution

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which…

craft_cms | Remote | Server-Side Request Forgery
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
6.9 MEDIUM
CVE-2026-27128 — Craft CMS's race condition in Token Service potentially allows for token usage greater th…

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validat…

craft_cms | Remote | Race Condition
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
7.0 HIGH
CVE-2026-27127 — Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separ…

craft_cms | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
5.9 MEDIUM
CVE-2026-27126 — Craft CMS has Stored XSS in Table Field via "HTML" Column Type

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` co…

craft_cms | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-26983 — ImageMagick: Invalid MSL <map> can result in a use after free

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` …

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-26981 — OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 and 3.4.0 through 3.4.…

openexr | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-26331 — yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) …

yt-dlp | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-26284 — ImageMagick has heap overflow in pcd decoder that leads to out of bounds read.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huf…

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-26283 — ImageMagick has possible infinite loop in JPEG encoder when using `jpeg:extent`

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue` statement in the JPEG extent binary search loop i…

imagemagick | Remote | Denial of Service
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-26198 — ormar is vulnerable to SQL Injection through aggregate functions min() and max()

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sq…

ormar | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-26066 — ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafte…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted profile contain invalid IPTC data may cause an infin…

imagemagick | Remote | Denial of Service
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-25989 — ImageMagick has integer overflow or wraparound and incorrect conversion between numeric t…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-on…

imagemagick | Remote | Denial of Service
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.2 HIGH
CVE-2026-1459 — Zyxel VMG3625-T50B Post-Authentication Command Injection Vulnerability

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated …

Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
Showing 20 of 5265 Results