Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-27486 — OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminate processes without …

openclaw | Remote | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
4.6 MEDIUM
CVE-2026-27485 — OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in in…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, skills/skill-creator/scripts/package_skill.py (a local helper script used when authors package skills) previously followed symlin…

openclaw | Information Disclosure
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
4.3 MEDIUM
CVE-2026-27484 — OpenClaw Discord moderation authorization used untrusted sender identity in tool-driven f…

OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, the Discord moderation action handling (timeout, kick, ban) uses sender identity from request parameters in tool-driven flows, in…

openclaw | Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-27482 — Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdo…

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. …

ray | Remote | Authentication
Feb 21, 2026 Mar 04, 2026
Feb 21, 2026
Mar 04, 2026
5.3 MEDIUM
CVE-2026-27480 — Static Web Server: Timing-Based Username Enumeration in Basic Authentication

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authenti…

static_web_server | Remote | Authentication
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2025-14339 — weMail <= 2.0.7 - Missing Authorization to Unauthenticated Form Deletion

The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to unauthorized form deletion in all versions up to, and …

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
7.7 HIGH
CVE-2026-27479 — Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon up…

wallos | Remote | Server-Side Request Forgery
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-2865 — itsourcecode Agri-Trading Online Shopping System HTTP POST Request productcontroller.php …

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler.…

Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
5.5 MEDIUM
CVE-2026-2864 — feng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path trave…

A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the function pictureDelete of the file PictureController.j…

Remote | Path Traversal
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-27470 — ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cau…

ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the …

zoneminder | Remote | Injection
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-27469 — Isso: Stored XSS via comment website field

Isso is a lightweight commenting server written in Python and JavaScript. In commits before 0afbfe0691ee237963e8fb0b2ee01c9e55ca2144, there is a stored Cross-Site Scripting (XSS) vulnerability affect…

Remote | Cross-Site Scripting
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
2.4 LOW
CVE-2026-27467 — BigBlueButton: Audio from participants to the server initially unmuted

BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state.…

bigbluebutton | Remote | Information Disclosure
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
8.2 HIGH
CVE-2026-27466 — BigBlueButton: Exposed ClamAV port enables Denial of Service

BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains inst…

bigbluebutton | Remote | Denial of Service
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.7 HIGH
CVE-2026-27464 — Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE

Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase ins…

metabase | Remote | Information Disclosure
Feb 21, 2026 Mar 02, 2026
Feb 21, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2026-27471 — ERP: Document access through endpoints due to missing validation

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorize…

erpnext | Remote | Authorization
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
8.7 HIGH
CVE-2026-27458 — LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description

LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authent…

linkace | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
9.2 CRITICAL
CVE-2026-27452 — ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the u…

asn1-ts | Remote | Information Disclosure
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
8.1 HIGH
CVE-2026-27206 — Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unse…

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The…

Remote | Information Disclosure
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2863 — feng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal

A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the function deleteFile of the file FileServiceImpl.java…

Remote | Path Traversal
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2861 — Foswiki Changes/Viewfile/Oops information disclosure

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is pos…

foswiki | Remote | Information Disclosure
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
Showing 20 of 5066 Results