Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.4 HIGH
CVE-2024-56373 — Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able t…

airflow | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.4 CRITICAL
CVE-2025-11165 — DotCMS Velocity Sandbox Escape Vulnerability

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by Sec…

dotcms | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.7 HIGH
CVE-2024-1524 — A local user can be impersonated when using federated authentication with Silent JIT Prov…

When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk that a local user store user's information may be replaced during the account p…

wso2_identity_server wso2_api_manager | Remote | Authentication
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
2.9 LOW
CVE-2026-1229 — Incorrect calculation in CIRCL secp384r1 CombinedMult

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signi…

circl | Remote | Cryptography
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40541 — SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Remote Code Execution Vulnerabi…

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requir…

serv-u | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40540 — SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative p…

serv-u | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40539 — SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative p…

serv-u | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.1 CRITICAL
CVE-2025-40538 — SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via d…

serv-u | Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
4.3 MEDIUM
CVE-2026-24314 — Information Disclosure vulnerability in S/4HANA (Manage Payment Media)

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality …

Remote | Authorization
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.2 HIGH
CVE-2025-15589 — MuYuCMS Template Management Template.php delete_dir_file path traversal

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulat…

muyucms | Remote | Path Traversal
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-15386 — Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment wit…

responsive_lightbox | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-3070 — SourceCodester Modern Image Gallery App upload.php cross site scripting

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filena…

modern_image_gallery_app | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3069 — itsourcecode Document Management System edtlbls.php sql injection

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to s…

Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3068 — itsourcecode Document Management System deluser.php sql injection

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to…

Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3067 — HummerRisk Archive Extraction CommandUtils.java extractZip path traversal

A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/uti…

hummerrisk | Remote | Path Traversal
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3066 — HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection

A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformU…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27461 — Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE …

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded a…

pimcore | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
6.7 MEDIUM
CVE-2026-3091 — Synology Presto Client DLL Injection Vulnerability

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in adv…

| Path Traversal
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3065 — HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult …

A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the component Cloud Task Dry-run. Performin…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3064 — HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection

A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreateService.java of the component Cloud Task Scheduler…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
Showing 20 of 4889 Results