Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-27471 — ERP: Document access through endpoints due to missing validation

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorize…

erpnext | Remote | Authorization
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
8.7 HIGH
CVE-2026-27458 — LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description

LinkAce is a self-hosted archive to collect website links. Versions 2.4.2 and below have a Stored Cross-site Scripting vulnerability through the Atom feed endpoint for lists (/lists/feed). An authent…

linkace | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
9.2 CRITICAL
CVE-2026-27452 — ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the u…

asn1-ts | Remote | Information Disclosure
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
8.1 HIGH
CVE-2026-27206 — Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unse…

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The…

Remote | Information Disclosure
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2863 — feng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal

A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the function deleteFile of the file FileServiceImpl.java…

Remote | Path Traversal
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
5.5 MEDIUM
CVE-2026-2861 — Foswiki Changes/Viewfile/Oops information disclosure

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is pos…

foswiki | Remote | Information Disclosure
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
9.4 CRITICAL
CVE-2026-27212 — Swiper has a Prototype Pollution Vulnerability

Swiper is a free and mobile touch slider with hardware accelerated transitions and native behavior. Versions 6.5.1 through 12.1.1 have a Prototype pollution vulnerability. The vulnerability resides i…

swiper | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
10.0 CRITICAL
CVE-2026-27211 — Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse

Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-b…

cloud_hypervisor | Remote | Path Traversal
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.1 MEDIUM
CVE-2026-27210 — Pannellum has a XSS vulnerability in hot spot attributes

Pannellum is a lightweight, free, and open source panorama viewer for the web. In versions 3.5.0 through 2.5.6, the hot spot attributes configuration property allowed any attribute to be set, includi…

pannellum | Remote | Cross-Site Scripting
Feb 21, 2026 Mar 02, 2026
Feb 21, 2026
Mar 02, 2026
4.3 MEDIUM
CVE-2026-27205 — Flask session does not add `Vary: Cookie` header when accessed in some ways

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a U…

flask | Remote | Misconfiguration
Feb 21, 2026 Feb 24, 2026
Feb 21, 2026
Feb 24, 2026
6.3 MEDIUM
CVE-2026-27199 — Werkzeug safe_join() allows Windows special device names

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previo…

werkzeug | Remote | Path Traversal
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
8.8 HIGH
CVE-2026-27198 — Formwork Improperly Manages Privileges During User Creation

Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although th…

formwork | Remote | Authorization
Feb 21, 2026 Mar 03, 2026
Feb 21, 2026
Mar 03, 2026
6.5 MEDIUM
CVE-2026-26047 — Moodle: moodle: uncontrolled resource consumption in tex formula editor leading to denial…

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution time limits could allow specially crafted formulas to…

moodle | Remote | Denial of Service
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.2 HIGH
CVE-2026-26046 — Moodle: moodle: improper input sanitization in tex filter administration setting

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled …

moodle | Remote | Injection
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
7.2 HIGH
CVE-2026-26045 — Moodle: moodle: improper validation in file restore functionality leading to remote code …

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lea…

moodle | Remote | Injection
Feb 21, 2026 Feb 26, 2026
Feb 21, 2026
Feb 26, 2026
6.5 MEDIUM
CVE-2026-2860 — feng_ha_ha/megagao ssm-erp/production_ssm EmployeeController.java improper authorization

A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the file EmployeeControl…

Remote | Authorization
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.1 CRITICAL
CVE-2026-27197 — Sentry: Improper Authentication on SAML SSO process allows user identity linking

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to t…

sentry | Remote | Authentication
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.1 HIGH
CVE-2026-27196 — Statamic affected by privilege escalation via stored Cross-site Scripting

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which a…

statamic | Remote | Cross-Site Scripting
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
9.8 CRITICAL
CVE-2026-27194 — D-Tale affected by Remote Code Execution through the /save-column-filter endpoint

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vuln…

d-tale | Remote | Injection
Feb 21, 2026 Feb 23, 2026
Feb 21, 2026
Feb 23, 2026
8.2 HIGH
CVE-2026-27193 — Feathers exposes internal headers via unencrypted session cookie

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the session cookie, whic…

feathers | Remote | Information Disclosure
Feb 21, 2026 Feb 25, 2026
Feb 21, 2026
Feb 25, 2026
Showing 20 of 5313 Results