Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-24314 — Information Disclosure vulnerability in S/4HANA (Manage Payment Media)

Under certain conditions SAP S/4HANA (Manage Payment Media) allows an authenticated attacker to access information which would otherwise be restricted. This could cause low impact on confidentiality …

s\/4hana_uiapfi70 s\/4hana_uis4h | Remote | Authorization
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-15589 — MuYuCMS Template Management Template.php delete_dir_file path traversal

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulat…

muyucms | Remote | Path Traversal
Feb 24, 2026 Feb 26, 2026
Feb 24, 2026
Feb 26, 2026
8.8 HIGH
CVE-2025-15386 — Responsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS

The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack due to flawed regex replacement rules that can be abused by posting a comment wit…

responsive_lightbox | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-3070 — SourceCodester Modern Image Gallery App upload.php cross site scripting

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filena…

modern_image_gallery_app | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3069 — itsourcecode Document Management System edtlbls.php sql injection

A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown function of the file /edtlbls.php. The manipulation of the argument field1 leads to s…

Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3068 — itsourcecode Document Management System deluser.php sql injection

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to…

Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3067 — HummerRisk Archive Extraction CommandUtils.java extractZip path traversal

A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/uti…

hummerrisk | Remote | Path Traversal
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3066 — HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection

A flaw has been found in HummerRisk up to 1.5.0. This vulnerability affects the function fixedCommand of the file hummer-common/hummer-common-core/src/main/java/com/hummer/common/core/utils/PlatformU…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27461 — Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE …

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded a…

pimcore | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.1 HIGH
CVE-2026-3091 — Synology Presto Client DLL Injection Vulnerability

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in adv…

presto_client | Path Traversal
Feb 24, 2026 Mar 04, 2026
Feb 24, 2026
Mar 04, 2026
8.8 HIGH
CVE-2026-3065 — HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult …

A vulnerability was detected in HummerRisk up to 1.5.0. This affects the function CommandUtils.commonExecCmdWithResult of the file CloudTaskService.java of the component Cloud Task Dry-run. Performin…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
8.8 HIGH
CVE-2026-3064 — HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection

A security vulnerability has been detected in HummerRisk up to 1.5.0. Affected by this issue is some unknown functionality of the file ResourceCreateService.java of the component Cloud Task Scheduler…

hummerrisk | Remote | Injection
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-3057 — a54552239 pearProjectApi Backend Task.php dateTotalForProject sql injection

A security flaw has been discovered in a54552239 pearProjectApi up to 2.8.10. Affected is the function dateTotalForProject of the file application/common/Model/Task.php of the component Backend Inter…

pearprojectapi | Remote | Injection
Feb 24, 2026 Mar 03, 2026
Feb 24, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2026-3054 — Alinto SOGo cross site scripting

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotel…

sogo | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 28, 2026
Feb 24, 2026
Feb 28, 2026
6.5 MEDIUM
CVE-2026-27129 — Cloud Metadata SSRF Protection Bypass via IPv6 Resolution

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which…

craft_cms | Remote | Server-Side Request Forgery
Feb 24, 2026 Mar 02, 2026
Feb 24, 2026
Mar 02, 2026
6.9 MEDIUM
CVE-2026-27128 — Craft CMS's race condition in Token Service potentially allows for token usage greater th…

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validat…

craft_cms | Remote | Race Condition
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
7.0 HIGH
CVE-2026-27127 — Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separ…

craft_cms | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
5.9 MEDIUM
CVE-2026-27126 — Craft CMS has Stored XSS in Table Field via "HTML" Column Type

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` co…

craft_cms | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-26983 — ImageMagick: Invalid MSL <map> can result in a use after free

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` …

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-26981 — OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 and 3.4.0 through 3.4.…

openexr | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
Showing 20 of 5237 Results