Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-27198 — Formwork Improperly Manages Privileges During User Creation

Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although th…

formwork | Remote | Authorization
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-26047 — Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial…

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to…

moodle | Remote | Denial of Service
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.2 HIGH
CVE-2026-26046 — Moodle: moodle: improper input sanitization in tex filter administration setting

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled …

moodle | Remote | Injection
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.2 HIGH
CVE-2026-26045 — Moodle: moodle: improper validation in file restore functionality leading to remote code …

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lea…

moodle | Remote | Injection
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2860 — feng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorization

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the file EmployeeControl…

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2026-27197 — Sentry: Improper Authentication on SAML SSO process allows user identity linking

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to t…

sentry | Remote | Authentication
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.1 HIGH
CVE-2026-27196 — Statamic affected by privilege escalation via stored Cross-site Scripting

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which a…

statamic | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-27194 — D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vuln…

d-tale | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-27193 — Feathers exposes internal headers via unencrypted session cookie

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the session cookie, whic…

feathers | Remote | Information Disclosure
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
8.1 HIGH
CVE-2026-27192 — Feathers has an origin validation bypass via prefix matching

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comparison, allowing at…

feathers | Remote | Misconfiguration
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
7.4 HIGH
CVE-2026-27191 — Feathers: Open Redirect in OAuth callback enables account takeover

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the base origin without…

feathers | Remote | Authentication
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
6.5 MEDIUM
CVE-2025-65995 — Apache Airflow: Disclosure of secrets to UI via kwargs

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might b…

airflow | Remote | Information Disclosure
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
8.3 HIGH
CVE-2026-27203 — eBay API MCP Server Affected by Environment Variable Injection

eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the…

Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-27202 — GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability

GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time o…

getsimple_cms | Remote | Information Disclosure
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.6 MEDIUM
CVE-2026-27189 — OpenSift: Race-prone local persistence could cause state corruption/loss

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below, use non-atomic and insufficiently synchronized local JSON persi…

opensift | Race Condition
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.1 HIGH
CVE-2026-27170 — OpenSift: SSRF risk in URL ingestion endpoint

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest allows overly permissive server-side fetch behavi…

opensift | Remote | Server-Side Request Forgery
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.9 HIGH
CVE-2026-27169 — OpenSift: Persistent XSS Chat Tool Rendering

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces usi…

opensift | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-27168 — SAIL: Heap-based Buffer Overflow in Sail-codecs-xwd

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to Heap-based Buffer Overflow through the XWD parser…

sail | Remote | Memory Corruption
Feb 21, 2026 Mar 02, 2026
Feb 21, 2026
Mar 02, 2026
8.7 HIGH
CVE-2026-27161 — Unauthenticated Information Disclosure via .htaccess Reliance in Sensitive Directories

GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride i…

getsimple_cms | Remote | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27147 — GetSimple CMS: Stored Cross-Site Scripting (XSS) via SVG File Upload (Authenticated)

GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload func…

getsimple_cms | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
Showing 20 of 5385 Results