Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-27118 — Cache poisoning in @sveltejs/adapter-vercel

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Versions of @sveltejs/adapter-vercel prior to 6.3.2 are vulnerable to cache poisoning. An internal qu…

kit | Remote | Misconfiguration
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
6.3 MEDIUM
CVE-2026-27113 — Liquid Prompt arbitrary command injection via crafted Git branch names in gitstatusd back…

Liquid Prompt is an adaptive prompt for Bash and Zsh. Starting in commit cf3441250bb5d8b45f6f8b389fcdf427a99ac28a and prior to commit a4f6b8d8c90b3eaa33d13dfd1093062ab9c4b30c on the master branch, ar…

| Injection
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.9 CRITICAL
CVE-2026-27112 — Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints

Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoints of both Kargo's legacy gRPC API and newer REST…

kargo | Remote | Injection
Feb 20, 2026 Feb 25, 2026
Feb 20, 2026
Feb 25, 2026
5.3 MEDIUM
CVE-2026-27111 — Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints

Kargo manages and automates the promotion of software artifacts. From v1.9.0 to v1.9.2, Kargo's authorization model includes a promote verb -- a non-standard Kubernetes "dolphin verb" -- that gates t…

kargo | Remote | Authorization
Feb 20, 2026 Feb 25, 2026
Feb 20, 2026
Feb 25, 2026
6.9 MEDIUM
CVE-2026-27026 — pypdf possibly has long runtimes for malformed FlateDecode streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a malformed /FlateDecode s…

pypdf | Denial of Service
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27025 — pypdf has possible long runtimes/large memory usage for large /ToUnicode streams

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requir…

pypdf | Denial of Service
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
6.9 MEDIUM
CVE-2026-27024 — pypdf has a possible infinite loop when processing TreeObject

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires accessing the children …

pypdf | Denial of Service
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-27022 — RediSearch Query Injection in @langchain/langgraph-checkpoint-redis

@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's fil…

Remote | Injection
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
7.8 HIGH
CVE-2026-0797 — GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…

gimp | Memory Corruption
Feb 20, 2026 Feb 24, 2026
Feb 20, 2026
Feb 24, 2026
7.8 HIGH
CVE-2026-0777 — Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability

Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction…

xmind | Information Disclosure
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2857 — D-Link DWR-M960 Port Forwarding Configuration Endpoint formPortFw sub_423E00 stack-based …

A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Port Forwarding Configuration Endpoint. Th…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2856 — D-Link DWR-M960 Filter Configuration Endpoint formFilter sub_424AFC stack-based overflow

A vulnerability was found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_424AFC of the file /boafrm/formFilter of the component Filter Configuration Endpoint. The mani…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-27190 — Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_p…

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.

deno | Remote | Injection
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
5.3 MEDIUM
CVE-2026-27020 — Photobooth has a XSS vulnerability in user input

Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inject scripts through unvalidated form inputs. This vulnerability is fixed in 1.0…

Remote | Cross-Site Scripting
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.3 CRITICAL
CVE-2026-25896 — fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE enti…

fast-xml-parser fast-xml-parser | Remote | Cross-Site Scripting
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
8.8 HIGH
CVE-2026-24892 — openITCOCKPIT has Unsafe Deserialization in openITCOCKPIT Changelog Handling

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP des…

openitcockpit | Remote | Injection
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
9.0 HIGH
CVE-2026-2855 — D-Link DWR-M960 DDNS Settings formDdns sub_4648F0 stack-based overflow

A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Handler. The manipulation of the argument su…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2854 — D-Link DWR-M960 NTP Configuration Endpoint formNtp sub_4611CC stack-based overflow

A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint. Executing a manipulation of the argumen…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
9.0 HIGH
CVE-2026-2853 — D-Link DWR-M960 System Log Configuration Endpoint formSysLog sub_462E14 stack-based overf…

A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Configuration Endpoint. Performing a manipulat…

dwr-m960_firmware dwr-m960 | Remote | Memory Corruption
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
7.7 HIGH
CVE-2026-2473 — Bucket Squatting in Vertex AI Experiments leads to RCE and Model Theft.

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker t…

Remote | Misconfiguration
Feb 20, 2026 Feb 23, 2026
Feb 20, 2026
Feb 23, 2026
Showing 20 of 5064 Results