Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-26988 — LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails t…

librenms | Remote | Injection
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.1 MEDIUM
CVE-2026-26987 — LibreNMS affected by reflected XSS via email field

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via email field. This issue has been fixed in version…

librenms | Remote | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
9.4 CRITICAL
CVE-2026-26980 — Ghost has a SQL Injection in its Content API

Ghost is a Node.js content management system. Versions 3.24.0 through 6.19.0 allow unauthenticated attackers to perform arbitrary reads from the database. This issue has been fixed in version 6.19.1.

ghost | Remote | Information Disclosure
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.9 MEDIUM
CVE-2026-26977 — Frappe Learning Management System exposes details of unpublished courses to unauthorized …

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished c…

learning | Remote | Authorization
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
7.1 HIGH
CVE-2026-26960 — node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain i…

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points t…

tar | Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
9.3 CRITICAL
CVE-2026-26065 — calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 2…

calibre | Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
9.3 CRITICAL
CVE-2026-26064 — calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execut…

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes …

calibre | Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-26975 — Music Assistant Server Path Traversal in Playlist Update API Allows Remote Code Execution

Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execut…

| Path Traversal
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2026-26974 — Sylde has Improper Control of Generation of Code

Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically imports **/*.plugin.{js,mjs} files including those from node_modules, so any malici…

slyde | Remote | Supply Chain
Feb 20, 2026 Mar 02, 2026
Feb 20, 2026
Mar 02, 2026
8.1 HIGH
CVE-2026-26967 — PJSIP has a Heap-based Buffer Overflow vulnerability in its H.264 unpacketizer

PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. …

pjsip | Remote | Memory Corruption
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-30416 — Acronis Cyber Protect Sensitive Data Disclosure and Manipulation Vulnerability

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (L…

cyber_protect | Authorization
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-30412 — Acronis Cyber Protect Sensitive Data Disclosure and Manipulation Vulnerability

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 …

cyber_protect | Authentication
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
10.0 CRITICAL
CVE-2025-30411 — Acronis Cyber Protect Sensitive Data Disclosure and Manipulation Vulnerability

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 …

cyber_protect | Authentication
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
9.8 CRITICAL
CVE-2025-30410 — Acronis Authentication Bypass

Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cy…

cyber_protect | Authentication
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-2605 — Tanium addressed an insertion of sensitive information into log file vulnerability in Tan…

Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.

tanos tanos | Remote | Information Disclosure
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
8.8 HIGH
CVE-2026-2435 — ASSET-7706

Tanium addressed a SQL injection vulnerability in Asset.

service_asset asset | Remote | Injection
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
4.7 MEDIUM
CVE-2026-2408 — Use-after-free in Cloud Workloads

Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.

Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2026-2350 — Tanium addressed an insertion of sensitive information into log file vulnerability in Int…

Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.

service_interact interact service_tds | Remote | Information Disclosure
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
5.8 MEDIUM
CVE-2026-27009 — OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in in…

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rendering assistant identity (name/avatar) into an inline `<script>` tag without sc…

openclaw | Cross-Site Scripting
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
6.8 MEDIUM
CVE-2026-27008 — OpenClaw hardened the skill download target directory validation

OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a bug in `download` skill installation allowed `targetDir` values from skill frontmatter to resolve outside the per-skill tools direct…

openclaw | Misconfiguration
Feb 20, 2026 Feb 20, 2026
Feb 20, 2026
Feb 20, 2026
Showing 20 of 5070 Results