Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-27128 — Craft CMS's race condition in Token Service potentially allows for token usage greater th…

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validat…

craft_cms | Remote | Race Condition
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
7.0 HIGH
CVE-2026-27127 — Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separ…

craft_cms | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
5.9 MEDIUM
CVE-2026-27126 — Craft CMS has Stored XSS in Table Field via "HTML" Column Type

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` co…

craft_cms | Remote | Cross-Site Scripting
Feb 24, 2026 Feb 27, 2026
Feb 24, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-26983 — ImageMagick: Invalid MSL <map> can result in a use after free

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the MSL interpreter crashes when processing a invalid `<map>` …

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
6.5 MEDIUM
CVE-2026-26981 — OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 and 3.4.0 through 3.4.…

openexr | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.8 HIGH
CVE-2026-26331 — yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) …

yt-dlp | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-26284 — ImageMagick has heap overflow in pcd decoder that leads to out of bounds read.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick lacks proper boundary checking when processing Huf…

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-26283 — ImageMagick has possible infinite loop in JPEG encoder when using `jpeg:extent`

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue` statement in the JPEG extent binary search loop i…

imagemagick | Remote | Denial of Service
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2026-26198 — ormar is vulnerable to SQL Injection through aggregate functions min() and max()

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sq…

ormar | Remote | Injection
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-26066 — ImageMagick has infinite loop when writing IPTCTEXT leads to denial of service via crafte…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted profile contain invalid IPTC data may cause an infin…

imagemagick | Remote | Denial of Service
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-25989 — ImageMagick has integer overflow or wraparound and incorrect conversion between numeric t…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-on…

imagemagick | Remote | Denial of Service
Feb 24, 2026 Feb 24, 2026
Feb 24, 2026
Feb 24, 2026
7.2 HIGH
CVE-2026-1459 — Zyxel VMG3625-T50B Post-Authentication Command Injection Vulnerability

A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated …

Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
8.8 HIGH
CVE-2025-13943 — Zyxel EX3301-T0 Post-Authentication Command Injection Vulnerability

A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execut…

Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2025-13942 — Zyxel EX3510-B0 UPnP Command Injection

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an…

Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
4.9 MEDIUM
CVE-2025-11848 — Zyxel Wake-on-LAN CGI Null Pointer Dereference Denial-of-Service Vulnerability

A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL…

Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
4.9 MEDIUM
CVE-2025-11847 — Zyxel VMG3625-T50B and WX3100-T0 Null Pointer Dereference DoS Vulnerability

A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABV…

Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.8 CRITICAL
CVE-2026-3053 — DataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authentication

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component Ope…

dinky | Remote | Authentication
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.7 HIGH
CVE-2026-3052 — DataLinkDC dinky Flink Proxy Controller FlinkProxyController.java proxyUba server-side re…

A vulnerability was found in DataLinkDC dinky up to 1.2.5. The impacted element is the function proxyUba of the file dinky-admin/src/main/java/org/dinky/controller/FlinkProxyController.java of the co…

dinky | Remote | Server-Side Request Forgery
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
7.5 HIGH
CVE-2026-25988 — ImageMagick's MSL image stack index not refreshed, leading to leaked images.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, sometimes msl.c fails to update the stack index, so an image i…

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
9.1 CRITICAL
CVE-2026-25987 — ImageMagick has heap buffer over-read in MAP image decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the MAP image …

imagemagick | Remote | Memory Corruption
Feb 24, 2026 Feb 25, 2026
Feb 24, 2026
Feb 25, 2026
Showing 20 of 5377 Results